Loading

Google Santa Integration

Stack 9.0.0 Serverless Observability Serverless Security

Version 3.24.0 (View all)
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic
Ingestion method(s) File

The Google Santa integration collects and parses logs from Google Santa, a security tool for macOS that monitors process executions and can blacklist/whitelist binaries.

The Google Santa integration was tested with logs from Santa 2022.4.

Google Santa is available for MacOS only.

The integration is by default configured to read logs from /var/db/santa/santa.log.

This is the Google Santa log dataset.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.