Skip to content

A–Z

Glossary

Plain-language definitions of the Unified Logging terms used across the tool and the blog.

dsc (shared-cache strings)
Files in /private/var/db/uuidtext/dsc holding the format strings of the dyld shared cache, used by most Apple framework log messages.
Firehose chunk
The tracev3 chunk (tag 0x6001) that holds regular Unified Log entries: log, activity, trace, signpost and loss events.
.logarchive
A portable macOS bundle holding a copy of the Unified Log store: tracev3 files, uuidtext and dsc strings, and timesync records.
Mach continuous time
The macOS clock, counting from boot and including sleep, used for Unified Log timestamps before conversion to UTC.
Oversize string
A tracev3 chunk (tag 0x6002) holding Unified Log argument data too large for its entry, sometimes stored in a later file.
<private> redaction
Why Unified Log messages show <private>: values marked private are hidden when logged unless a profile enables private data.
Signpost
A Unified Log event marking the start, end or a point of an operation, used for performance measurement rather than diagnostics.
Statedump
A Unified Log record (tracev3 tag 0x6003) where a process dumps a block of state, such as a plist, a protobuf or an object.
Subsystem and category
The reverse-DNS subsystem and the category an os_log message is logged under, such as com.apple.TCC and access.
timesync
Records in /private/var/db/diagnostics/timesync that convert Unified Log Mach times into wall-clock UTC for each boot.
tracev3
The binary file format macOS uses to store Unified Log entries: a header, catalogs and LZ4-compressed chunksets of log entries.
Unified Logging
The single logging system of macOS since 10.12 Sierra, where the kernel, Apple daemons and os_log clients write their messages.
uuidtext
Files under /private/var/db/uuidtext that hold the format strings of each binary, needed to render Unified Log messages.