Skip to content

log show NDJSON Exports and Unified Log Timelines

Export macOS Unified Logs with log show (ndjson, json, text styles), avoid time-zone traps, compare parsers and build CSV or Timesketch timelines.

Published on 4 min read

TL;DR. For a timeline, export with log show --info --debug --timezone UTC --style ndjson: one JSON object per entry, every field kept, times in UTC. Know which options you used, because the defaults hide Info, Debug and signposts. The Unified Log Parser reads these exports, and writes CSV, NDJSON and Timesketch files from tracev3 or from exports.

The output styles of log show

log show accepts five styles (log help show lists them): default, syslog, json, ndjson and compact.

StyleOne entry isKeepsWatch out for
ndjsonone JSON object per lineevery fieldlarge files
jsonan object in one big arrayevery fieldmust be parsed as a whole or streamed
defaulta text line + continuation linestime, thread, type, activity, PID, TTL, process, sender, subsystem:categorymulti-line messages
sysloga syslog-like linetime, host, process, PID, senderno type column
compacta short linetype code, process, PID, threadmilliseconds only, no UTC offset

NDJSON fields include timestamp, eventType, messageType, processImagePath, processID, threadID, userID, senderImagePath, subsystem, category, activityIdentifier, bootUUID, formatString and eventMessage; signposts add signpostName, signpostType and signpostScope. The last line of an NDJSON export is a summary ({"count":…,"finished":1}), not an entry.

Options that change what you get

log show --archive case.logarchive --info --debug --timezone UTC --style ndjson > case.ndjson
  • --info and --debug: without them, only Default, Error and Fault messages are shown (plus activities and state).
  • --signpost: signposts are hidden unless asked for.
  • --timezone UTC: otherwise each entry is printed in the time zone recorded with it, and the TZ variable is not honoured on current releases.
  • --start / --end / --last: limit the window; accepted formats include YYYY-MM-DD HH:MM:SS and an explicit offset.
  • --predicate: filter at export time — useful, but you cannot recover what you filtered out.

Write the command into your notes: two exports of the same archive with different options are different evidence.

Reading exports in the parser

Drop an .ndjson, .json or text export on the parser. Exports are streamed in 8 MB chunks, so a 400 MB JSON array is fine. Text styles are recognised from their header line (Timestamp Thread Type Activity PID TTL) or from the first lines; continuation lines are folded into the previous message. A compact-style export is read as UTC and flagged, because the style carries no offset.

Parsers compared

ToolInputNotes
log show / Consolearchive or live store, on a Macthe reference rendering
Mandiant macos-unifiedlogstracev3 + uuidtext + timesync, any OSRust library and unifiedlog_iterator example (CSV / JSONL)
Plaso unified_logging parsertracev3 in an image or foldername it explicitly: it is not in the default macOS preset
mac_apt UNIFIEDLOGEXPORTdisk imageexports the files for a parser
Unified Log Parserarchive, folders, ZIP / tar.gz, exportsmacos-unifiedlogs in WebAssembly with log show-fidelity fixes, filters, triage, exports

Validated on a real archive, the Unified Log Parser matched log show on about 99% of log, activity and state messages. The remaining differences are mostly Apple's own object decoders (for example a host name rendered by log show where the parser shows <private>), truncation markers on very long arguments, and signposts, which log show renders with internal description markers.

Building a timeline

From the parser, Export writes the entries shown — current filters and time range — in four formats:

  • CSV: one row per entry with timestamp_utc, type, process name and path, PID, thread, user ID, subsystem, category, sender, activity, message, format string, boot UUID, triage flags and source file. Cells starting with =, +, - or @ are quoted to prevent spreadsheet formula injection.
  • NDJSON: log show field names with UTC timestamps (2026-09-14 10:05:02.610004+0000), plus triageFlags and evidence. Re-importable.
  • JSON: the same entries inside an envelope recording the source files, the time range and the filters.
  • Timesketch CSV: message, datetime, timestamp_desc and timestamp (microseconds) columns, ready to import.

Export a narrow, filtered window per question (for example "TCC and Terminal, 10:00–10:55") rather than the whole store: timelines are for reading.

Next: the triage queries to decide what goes into the timeline, or the browser walkthrough.

Related articles

Step by step: open a macOS .logarchive, diagnostics folder or log show export in the free Unified Log Parser, triage findings, set a time range and export.
What macOS Unified Logs record, where tracev3, uuidtext and timesync live, what they can and cannot prove, and a workflow to read them for an investigation.
Collect macOS Unified Logs with log collect, a raw copy of diagnostics and uuidtext, UAC, Velociraptor or mac_apt, and avoid the gaps that break parsing.