You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* Rebranding Kandji to Iru
* Updated source type name
* chore: trigger CI
* Updated readme
* Updated Iru(Kandji) to Iru (Kandji)
---------
Co-authored-by: Gustavo Mora <tavo.mora92@hotmail.com>
[Kandji][1] is an Apple device management and security platform that helps organizations automate deployment, enforce compliance, and secure macOS and iOS devices.
3
+
[Iru][1](formerly known as Kandji) is a unified, AI-powered IT and security platform that helps organizations protect users, applications, and devices by replacing multiple solutions with a single, automated system.
4
4
5
5
This integration ingests the following logs:
6
6
-**Audit**: Provides information about security events, device lifecycle changes, and admin/user actions.
7
7
-**Threats**: Provides information about detected threats, including classification, status, affected devices, associated files, processes, and blueprints.
8
8
-**Detections**: Lists detected findings, their severity, affected devices and applications, and associated blueprints.
9
9
10
-
Integrate Kandji with Datadog to gain insights into audit, and threats and detections logs using pre-built dashboard visualizations. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating search and detailed insights. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.
10
+
Integrate Iru (Kandji) with Datadog to gain insights into audit, and threats and detections logs using pre-built dashboard visualizations. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating search and detailed insights. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.
11
11
12
12
## Setup
13
13
14
-
### Prerequisites
14
+
### Generate API Token from the Iru (Kandji) platform
15
15
16
-
- Kandji MDM, EDR and Vulnerability Management.
17
-
18
-
### Generate API Token from the Kandji Platform
19
-
20
-
1. Log in to Kandji Platform using **Admin** or **Owner** account and click on **Settings**.
16
+
1. Log in to Iru (Kandji) platform using **Admin** or **Owner** account and click on **Settings**.
21
17
2. Click the **Access** tab.
22
18
3. Scroll down to the **API Token** section and click the **Add Token** button.
23
19
4. Enter **Name** and **Description** for your API token.
@@ -30,32 +26,35 @@ Integrate Kandji with Datadog to gain insights into audit, and threats and detec
30
26
11. Under **API Token** section, locate your domain. For example, your organizations API Domain will be:
"content": "This dashboard provides a comprehensive summary of Audit logs.\n\nFor more information, see the [Kandji Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
29
+
"content": "This dashboard provides a comprehensive summary of Iru (Kandji) audit logs.\n\nFor more information, see the [Iru (Kandji) Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
"content": "This dashboard provides a comprehensive summary of Detection logs.\n\nFor more information, see the [Kandji Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
29
+
"content": "This dashboard provides a comprehensive summary of Iru (Kandji) detection logs.\n\nFor more information, see the [Iru (Kandji) Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
"content": "[Kandji](https://www.kandji.io/) is an Apple device management and security platform that helps organizations automate deployment, enforce compliance, and secure macOS and iOS devices.\n\nThis dashboard offers a comprehensive summary of all logs.\n\nFor more information, see the [Kandji Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
29
+
"content": "[Iru](https://www.iru.com/) (formerly known as Kandji) is a unified, AI-powered IT and security platform that helps organizations protect users, applications, and devices by replacing multiple point solutions with a single, automated system.\n\nThis dashboard provides a comprehensive summary of all Iru (Kandji) logs.\n\nFor more information, see the [Iru (Kandji) Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
30
30
"background_color": "white",
31
31
"font_size": "14",
32
32
"text_align": "left",
@@ -559,7 +559,7 @@
559
559
"id": 2768469841692041,
560
560
"definition": {
561
561
"type": "note",
562
-
"content": "\nDatadog Cloud SIEM analyzes and correlates **Kandji** Events to detect threats to your environment in real time. If you don't see signals please make sure you've enabled [Datadog Cloud SIEM](/security). ",
562
+
"content": "\nDatadog Cloud SIEM analyzes and correlates **Iru (Kandji)** Events to detect threats to your environment in real time. If you don't see signals please make sure you've enabled [Datadog Cloud SIEM](/security). ",
"content": "This dashboard provides a comprehensive summary of Threats.\n\nFor more information, see the [Kandji Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
29
+
"content": "This dashboard provides a comprehensive summary of Iru (Kandji) Threats.\n\nFor more information, see the [Iru (Kandji) Documentation](https://docs.datadoghq.com/integrations/kandji/).\n\n**Tips**:\n - Use the timeframe selector in the upper-right corner of the dashboard to change the default timeframe.\n - Clone this dashboard to rearrange, modify, and add widgets and visualizations.\n\n",
0 commit comments