Loading

JumpCloud

Version 1.19.0 (View all)
Subscription level
What's this?
Basic
Developed by
What's this?
Community
Ingestion method(s) API
Minimum Kibana version(s) 9.0.0
8.13.0

The JumpCloud integration allows you to monitor events related to the JumpCloud Directory as a Service via the Directory Insights API.

You can find out more about JumpCloud and JumpCloud Directory Insights here

A single data stream named "jumpcloud.events" is used by this integration.

An Elastic Stack with an Elastic Agent is a fundamental requirement.

An established JumpCloud tenancy with active users is the the other requirement. Basic Directory Insights API access is available to all subscription levels.

Note

The lowest level of subscription currently has retention limits, with access to Directory Insights events for the last 15 days at most. Other subscriptions levels provide 90 days or longer historical event access.

A JumpCloud API key is required, the JumpCloud documentation describing how to create one is here

This JumpCloud Directory Insights API is documented here

Ensure you have created a JumpCloud admin API key that you have access to, refer to the link above which provides instructions how to create one.

  1. In Kibana go to Management > Integrations
  2. In "Search for integrations" search bar type JumpCloud
  3. Click on "JumpCloud" integration from the search results.
  4. Click on Add JumpCloud button to add the JumpCloud integration.
  5. Configure the integration as appropriate
  6. Assign the integration to a new Elastic Agent host, or an existing Elastic Agent host

Example of Add JumpCloud Integration

The integration collects events from JumpCloud's Directory Insights API. You can control which event categories are collected using the services setting. The default value is all, which collects events from every service.

The supported service values are:

Service Description
all Events from all services.
access_management Access management activity.
aigw AI gateway activity.
alert Alert service events.
asset_management Asset management activity.
di_events Generic Directory Insights events.
directory Admin Portal and User Portal activity, including admin changes and authentications.
genai Generative AI activity.
ldap User authentications to LDAP, including LDAP Bind and Search events.
mdm MDM command results.
notifications Notification activity.
object_storage Object storage activity.
password_manager JumpCloud password manager activity.
radius User authentications to RADIUS, used for Wi-Fi and VPNs.
reports Report activity.
software Application changes on macOS, Windows, and Linux devices.
sso User authentications to SAML applications.
systems User authentications to macOS, Windows, and Linux systems, including agent-related events.

The JumpCloud events dataset provides events from JumpCloud Directory Insights events that have been received.

All JumpCloud Directory Insights events are available in the jumpcloud.events field group.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.