Skip to content

Series

Investigating with Unified Logs

3 posts in this series. Read them in order or jump to any one.

  1. How to Collect macOS Unified Logs for Forensics

    Collect macOS Unified Logs with log collect, a raw copy of diagnostics and uuidtext, UAC, Velociraptor or mac_apt, and avoid the gaps that break parsing.

  2. macOS Unified Log Triage: Queries That Matter

    log show predicates and parser filters for sudo, SSH, Screen Sharing, TCC, Gatekeeper, XProtect, launch agents, login items, USB mounts and the log command.

  3. Open a .logarchive in Your Browser, on Any OS

    Step by step: open a macOS .logarchive, diagnostics folder or log show export in the free Unified Log Parser, triage findings, set a time range and export.

All posts in this series

Collect macOS Unified Logs with log collect, a raw copy of diagnostics and uuidtext, UAC, Velociraptor or mac_apt, and avoid the gaps that break parsing.
log show predicates and parser filters for sudo, SSH, Screen Sharing, TCC, Gatekeeper, XProtect, launch agents, login items, USB mounts and the log command.
Step by step: open a macOS .logarchive, diagnostics folder or log show export in the free Unified Log Parser, triage findings, set a time range and export.