log show NDJSON Exports and Unified Log Timelines
Export macOS Unified Logs with log show (ndjson, json, text styles), avoid time-zone traps, compare parsers and build CSV or Timesketch timelines.
TL;DR. For a timeline, export with log show --info --debug --timezone UTC --style ndjson: one JSON object per entry, every field kept, times in UTC. Know which options you used, because the defaults hide Info, Debug and signposts. The Unified Log Parser reads these exports, and writes CSV, NDJSON and Timesketch files from tracev3 or from exports.
The output styles of log show
log show accepts five styles (log help show lists them): default, syslog, json, ndjson and compact.
| Style | One entry is | Keeps | Watch out for |
|---|---|---|---|
ndjson | one JSON object per line | every field | large files |
json | an object in one big array | every field | must be parsed as a whole or streamed |
default | a text line + continuation lines | time, thread, type, activity, PID, TTL, process, sender, subsystem:category | multi-line messages |
syslog | a syslog-like line | time, host, process, PID, sender | no type column |
compact | a short line | type code, process, PID, thread | milliseconds only, no UTC offset |
NDJSON fields include timestamp, eventType, messageType, processImagePath, processID, threadID, userID, senderImagePath, subsystem, category, activityIdentifier, bootUUID, formatString and eventMessage; signposts add signpostName, signpostType and signpostScope. The last line of an NDJSON export is a summary ({"count":…,"finished":1}), not an entry.
Options that change what you get
log show --archive case.logarchive --info --debug --timezone UTC --style ndjson > case.ndjson
--infoand--debug: without them, only Default, Error and Fault messages are shown (plus activities and state).--signpost: signposts are hidden unless asked for.--timezone UTC: otherwise each entry is printed in the time zone recorded with it, and theTZvariable is not honoured on current releases.--start/--end/--last: limit the window; accepted formats includeYYYY-MM-DD HH:MM:SSand an explicit offset.--predicate: filter at export time — useful, but you cannot recover what you filtered out.
Write the command into your notes: two exports of the same archive with different options are different evidence.
Reading exports in the parser
Drop an .ndjson, .json or text export on the parser. Exports are streamed in 8 MB chunks, so a 400 MB JSON array is fine. Text styles are recognised from their header line (Timestamp Thread Type Activity PID TTL) or from the first lines; continuation lines are folded into the previous message. A compact-style export is read as UTC and flagged, because the style carries no offset.
Parsers compared
| Tool | Input | Notes |
|---|---|---|
log show / Console | archive or live store, on a Mac | the reference rendering |
| Mandiant macos-unifiedlogs | tracev3 + uuidtext + timesync, any OS | Rust library and unifiedlog_iterator example (CSV / JSONL) |
Plaso unified_logging parser | tracev3 in an image or folder | name it explicitly: it is not in the default macOS preset |
mac_apt UNIFIEDLOGEXPORT | disk image | exports the files for a parser |
| Unified Log Parser | archive, folders, ZIP / tar.gz, exports | macos-unifiedlogs in WebAssembly with log show-fidelity fixes, filters, triage, exports |
Validated on a real archive, the Unified Log Parser matched log show on about 99% of log, activity and state messages. The remaining differences are mostly Apple's own object decoders (for example a host name rendered by log show where the parser shows <private>), truncation markers on very long arguments, and signposts, which log show renders with internal description markers.
Building a timeline
From the parser, Export writes the entries shown — current filters and time range — in four formats:
- CSV: one row per entry with
timestamp_utc, type, process name and path, PID, thread, user ID, subsystem, category, sender, activity, message, format string, boot UUID, triage flags and source file. Cells starting with=,+,-or@are quoted to prevent spreadsheet formula injection. - NDJSON:
log showfield names with UTC timestamps (2026-09-14 10:05:02.610004+0000), plustriageFlagsandevidence. Re-importable. - JSON: the same entries inside an envelope recording the source files, the time range and the filters.
- Timesketch CSV:
message,datetime,timestamp_descandtimestamp(microseconds) columns, ready to import.
Export a narrow, filtered window per question (for example "TCC and Terminal, 10:00–10:55") rather than the whole store: timelines are for reading.
Next: the triage queries to decide what goes into the timeline, or the browser walkthrough.