Skip to content

Guide: macOS audit logging and unified log #28

@davidwhittington

Description

@davidwhittington

What gets logged, where logs live (Unified Logging, /var/log, ASL), and how to query them. Topics: log show syntax and useful filters, finding SSH auth events, spotting failed sudo attempts, setting log retention policy, and what to look for when investigating an incident. Complements the security audit script which captures point-in-time state.

Metadata

Metadata

Assignees

No one assigned

    Labels

    docsDocumentation improvementsguideStep-by-step guides

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions