Open a .logarchive in Your Browser, on Any OS
Step by step: open a macOS .logarchive, diagnostics folder or log show export in the free Unified Log Parser, triage findings, set a time range and export.
TL;DR. The Unified Log Parser decodes macOS Unified Logs in a browser tab: drop a .logarchive (or the diagnostics and uuidtext folders, a ZIP, a UAC .tar.gz, or a log show export) and you get findings, a time-range strip, filters and exports — on Windows, Linux or macOS, with nothing uploaded. This walkthrough uses the built-in synthetic sample.
Step 1: Load the logs
Open the home page and drop your files. The parser recognises tracev3 files by their first bytes (00 10 00 00), uuidtext and dsc files by their paths, and exports by their content, so folder names do not matter as long as the uuidtext/XX/… layout is kept. A .logarchive is a folder: drag it in, or zip it with ditto first.
Large stores (a full Persist folder can hold several million entries) take a minute; the progress line names each file. If memory is tight, open Import options before dropping: keep only a time window, or skip signposts, Info or Debug entries while reading.
To follow along, click Try a sample. It loads a synthetic NDJSON export of the Mac FIN-MBP-03 on 14 September 2026, generated by a script in the project: about 700 entries of ordinary background activity with a fictional intrusion woven in.
Step 2: Check the sources
The workspace opens full screen (Esc to leave). Look at Sources first. For tracev3 input it shows the hardware model, the macOS build, the boot sessions, how many uuidtext and dsc files were available, and the timesync records. Warnings appear when string files or timesync are missing, when some messages could not be fully rendered ("unresolved"), or when an import option left entries out.
Step 3: Review the findings
The Findings tab groups entries matched by curated rules: authentication failures, sudo, sensitive TCC permissions, Gatekeeper decisions, launch agents and login items, volume mounts, shell commands and more. Each card says why it matters, the first and last time, the processes involved and example entries.
In the sample, the story reads top to bottom:
- 10:04 Screen Sharing: one failed, then a successful authentication for
dana.whitlockfrom203.0.113.45. - 10:06 Safari downloads
tools.zipfromfiles.example; the file is quarantined. - 10:07
syspolicydfinds the binary is not notarized; the user chooses Open Anyway. - 10:08–10:09 Terminal starts and receives Full Disk Access (
kTCCServiceSystemPolicyAllFiles). - 10:12–10:13
sudo(one wrong password) bootstraps a LaunchAgent,com.example.updater.plist, and Background Task Management registers it. - 10:36–10:47 a USB volume
EXFILis mounted, files staged in~/Library/Caches/.sync/are copied to it withditto, Safari openstransfer.example, the volume is ejected. - 10:49–10:50 the
logcommand is used to read the sudo entries; the screen is locked and the session ends.
None of these alone proves an intrusion; together, within 46 minutes of one session, they tell a story worth writing up.
Step 4: Focus the time range
The density strip shows entries over time. By default it spans the 1st to 99th percentile, so one entry with a bad clock does not squash the rest; "+N earlier / later" notes what is outside. Drag to select, use the keyboard on the handles (one step is one bar), type bounds to the second, or pick a preset. From any entry, Around ±5 min / ±1 h / ±24 h centers the range on it. The range applies to every count, finding and export, and is kept in the page address (#from=…&to=…) so a reload or a shared link restores it. In the sample, Show 10:00–10:55 UTC sets the incident window.
Step 5: Read the log
The Log tab lists every entry of the range, virtualised so millions of rows scroll smoothly. Search message, process, subsystem and category at once (regular expressions and case-sensitive matching are toggles), choose types, or open Fields to filter process, subsystem, category and PID. Terms are comma-separated, !term excludes and =term matches exactly — !mdworker, !WindowServer quietens the noise. The presets above the table apply common DFIR filters in one click. Click a row for all its fields, the flags it matched, and pivots: this process, this PID, this subsystem.
Step 6: Export
Export writes the entries currently shown — filters and time range applied — as CSV, NDJSON with log show field names (re-importable here or in other tools), JSON with metadata about the source files, range and filters, or Timesketch CSV. File names carry the range, for example …_2026-09-14T100000Z-2026-09-14T105500Z.csv. See exporting and building timelines.
Limits to keep in mind
Rendering follows Mandiant's macos-unifiedlogs parser, validated against log show on a real archive (about 99% of log messages identical); signposts are presented differently. Confirm key entries with log show for a report. The triage queries article explains what each finding looks for.