Skip to content

macOS Logging and Detection: Unified Log and Endpoint Security

Use the macOS unified log, Endpoint Security, eslogger, sysdiagnose, osquery and Santa to gain visibility and detect suspicious activity on Macs.

Published on 7 min read

Hardening reduces the attack surface; logging tells you when something gets through anyway, or when a control drifts. macOS has rich telemetry, but it is spread across the unified log, the Endpoint Security framework, and diagnostic tools, and none of it is forwarded anywhere by default. This guide covers how to query the unified log, which predicates are useful for security work, how Endpoint Security underpins modern EDR on the Mac, and which open-source tools help you collect and act on the data.

The unified log

Since macOS 10.12 Sierra, most system and application logging goes through the unified logging system. Messages are stored in a compressed binary format under /var/db/diagnostics with supporting data in /var/db/uuidtext, and are read with the log command or the Console app. Each message carries metadata such as the process, subsystem, category, log level and timestamp, which makes structured queries possible.

Log levels are default, info, debug, error and fault. Info and debug messages are often kept only in memory or for a short time, and are hidden from queries unless you ask for them.

Querying with log show and log stream

log show queries stored logs; log stream follows messages live. Both accept a predicate written in Apple's NSPredicate syntax.

# Last hour of sudo activity
log show --last 1h --predicate 'process == "sudo"'

# Live TCC (privacy permission) activity
log stream --predicate 'subsystem == "com.apple.TCC"'

# Include info and debug messages, compact output
log show --last 30m --info --debug --style compact --predicate 'process == "sshd"'

# Search message text
log show --last 1d --predicate 'eventMessage CONTAINS[c] "failed"'

Useful predicate fields:

FieldExampleNotes
processprocess == "sudo"Name of the logging process
subsystemsubsystem == "com.apple.TCC"Reverse-DNS subsystem set by the developer
categorycategory == "access"Subdivision within a subsystem
eventMessageeventMessage CONTAINS "..."Message text; [c] makes it case-insensitive
messageTypemessageType == errorFilter by level
senderImagePathsenderImagePath CONTAINS "..."Binary or library that emitted the message

Predicates combine with AND, OR and parentheses. Keep queries narrow: an unfiltered log show over a day produces an enormous amount of output.

Security-relevant starting points

These are reliable starting points for investigations:

  • process == "sudo": privilege escalation attempts and commands run with sudo. See the accounts and least privilege guide.
  • subsystem == "com.apple.TCC": privacy permission requests, grants and denials. See the TCC guide.
  • process == "sshd": Remote Login sessions, which should be rare if Remote Login is disabled as recommended in the firewall guide.
  • process == "screensharingd": Screen Sharing connections.
  • process == "loginwindow": login and screen unlock activity.

Subsystem names for components such as XProtect and XProtect Remediator change between releases. Confirm them on your current macOS version with log stream before building detections on them.

Exporting and collecting

log collect captures a log archive for offline analysis on another Mac:

sudo log collect --last 2h --output /tmp/incident.logarchive
log show /tmp/incident.logarchive --predicate 'process == "sudo"'

Private data redaction

Dynamic values that developers mark as private are shown as <private>. This protects user data but can hide exactly what you need during an investigation. The system logging configuration profile payload (com.apple.system.logging) can enable private data logging. Treat that as a temporary investigative measure: it writes sensitive data, such as user names and file paths, into logs that local admins can read.

Retention and forwarding

The unified log is size-bounded, so how long entries survive depends on volume. Busy Macs can lose older entries within days. There is no built-in mechanism to forward the unified log to a SIEM. If you need history, collect relevant events continuously with an agent, whether an EDR product, osquery or a dedicated log shipper, and send them to central storage.

OpenBSM audit: deprecated

Historically, macOS shipped the OpenBSM audit subsystem, configured in /etc/security/audit_control and read with praudit. Apple deprecated it in macOS 11 Big Sur in favor of Endpoint Security. You may still see audit settings in compliance baselines such as those generated by the mSCP and CIS benchmarks guide, but do not build new detection pipelines on it.

Endpoint Security framework

Endpoint Security (ES) is the supported kernel-to-user-space interface for security tools on macOS. It replaced the need for security kernel extensions. An ES client subscribes to event types and receives a message for each matching event, with rich context about the process, including its code signing information.

There are two event families:

  • NOTIFY events report something that already happened, such as a process executing or a file being created.
  • AUTH events ask the client for a decision before the action completes, for example allowing or denying an exec or a file open. The client must respond within a deadline, or the system proceeds without it.

Commonly used event types include:

EventTypeUse
ES_EVENT_TYPE_NOTIFY_EXEC / ES_EVENT_TYPE_AUTH_EXECProcessProcess execution monitoring and binary authorization
ES_EVENT_TYPE_NOTIFY_FORK, ES_EVENT_TYPE_NOTIFY_EXITProcessProcess tree reconstruction
ES_EVENT_TYPE_NOTIFY_OPEN / ES_EVENT_TYPE_AUTH_OPENFileFile access monitoring and protection
ES_EVENT_TYPE_NOTIFY_CREATE, ES_EVENT_TYPE_NOTIFY_RENAME, ES_EVENT_TYPE_NOTIFY_UNLINKFileFile system changes
ES_EVENT_TYPE_NOTIFY_BTM_LAUNCH_ITEM_ADDPersistenceNew login items, launch agents and daemons (macOS 13+)
ES_EVENT_TYPE_NOTIFY_XP_MALWARE_DETECTEDDetectionXProtect malware detections (macOS 13+)

Newer releases have added events for areas such as authentication, sudo, profile installation and TCC changes. Check Apple's Endpoint Security documentation for the events available on your minimum supported OS.

What an EDR needs on macOS

A production ES client requires:

  • The Endpoint Security client entitlement, which Apple grants to developers on request. Unsigned or unentitled tools cannot subscribe.
  • Packaging as a system extension, which must be approved by the user or allowed through the com.apple.system-extension-policy payload.
  • Full Disk Access, granted through a PPPC profile (com.apple.TCC.configuration-profile-policy) when deployed at scale.
  • Often a network extension and notification permissions, depending on the product.

Delivering these through MDM, as described in the MDM and configuration profiles guide, avoids users seeing approval prompts and prevents them from disabling the agent.

Built-in and open-source tooling

eslogger

macOS 13 Ventura added eslogger, a built-in command that prints Endpoint Security NOTIFY events as JSON. It is ideal for learning ES and for quick investigations, and Apple does not position it as a production agent. The terminal running it needs Full Disk Access.

# List supported event names
eslogger --list-events

# Stream process executions as JSON
sudo eslogger exec

sysdiagnose

sysdiagnose collects a large diagnostic bundle including logs, process lists and system state. Run sudo sysdiagnose, or press Shift-Control-Option-Command-Period. The archive is written to /var/tmp. It is useful when you need a broad snapshot of a Mac for triage, and it can contain sensitive data, so handle it accordingly.

Background Task Management

Persistence through launch agents, daemons and login items is tracked by Background Task Management. sudo sfltool dumpbtm lists registered items, which makes it a quick persistence review.

osquery, Santa and others

  • osquery exposes system state as SQL tables and, when its Endpoint Security integration is enabled, can record process and file events. It is a common way to inventory and hunt across a fleet.
  • Santa is an open-source binary authorization system built on Endpoint Security, now maintained by North Pole Security. Even in monitor mode, its execution logs are valuable telemetry. See the Gatekeeper and XProtect guide.
  • Commercial EDR products combine ES telemetry with detection content, response actions and central storage.

Verify it

# Confirm the unified log is queryable and recent
log show --last 5m --style compact | tail -n 5

# Check TCC events are being logged
log show --last 1h --predicate 'subsystem == "com.apple.TCC"' | head

# List installed system extensions (EDR agents appear here)
systemextensionsctl list

# Review persistent background items
sudo sfltool dumpbtm | less

In systemextensionsctl list, your EDR's extension should show as activated and enabled. If it is waiting for user approval, check the system extension and PPPC profiles.

Common pitfalls

  • Assuming logs are retained. The unified log rotates quickly on busy Macs. Collect continuously if you need history.
  • Leaving private data logging on. Enable it only for investigations, then remove the profile.
  • Relying on OpenBSM. It is deprecated. Move detections to Endpoint Security based tools.
  • EDR without MDM profiles. Missing Full Disk Access or system extension approval produces an agent that looks installed but sees little.
  • Guessing subsystem names. Validate predicates on the target OS version before turning them into alerts.

Checklist

  • EDR or ES-based agent deployed with system extension and Full Disk Access profiles.
  • Relevant events forwarded to central storage with defined retention.
  • Saved log predicates for sudo, TCC, remote access and login activity.
  • Persistence reviewed with sfltool dumpbtm or equivalent telemetry.
  • Incident procedure includes log collect and sysdiagnose capture.