Iru Logs

Connecting Iru logs to your Panther Console

Overview

Panther supports ingesting Iru audit logs via an AWS S3 Data Transport source.

Iru (formerly Kandji) is a Mobile Device Management (MDM) and endpoint management platform for Apple, Windows, and Android devices. Panther supports ingesting audit logs from Iru to monitor device management activities, policy compliance events, and security-related actions.

Learn more about Iru audit logs in the Iru API documentation.

How to onboard Iru logs to Panther

Step 1: Create a new Iru source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Iru," then click its tile.

  4. In the upper-right corner, click Start Setup.

Step 2: Export Iru logs to S3

Supported log types

Iru.Audit

Last updated

Was this helpful?