macOS OSLog (im_macoslog)
This module collects logs from macOS’s unified logging system (ULS) using Apple’s OSLog API, which is available starting with macOS 10.15 (Catalina). For older macOS versions, use the macOS ULS input module instead.
| To examine the supported platforms, see the list of installation packages. |
Configuration
The im_macoslog module accepts the following directives in addition to the common module directives.
Optional directives
Set this directive to the number of seconds the module subtracts from the current time to define a cutoff when reading new records. New records may not be immediately available through the OSLog API, so reading up to the current time risks silently missing them. Increase this value if you notice recent records missing from the output. Decrease it to reduce collection latency but risk occasionally missing very recent records. This directive accepts fractional values, for example, |
|||||||||||||||||||||||||||||||||||||
Set this directive to the minimum severity level to collect.
The accepted values, from least to most severe, are |
|||||||||||||||||||||||||||||||||||||
Set this directive to the number of seconds between checks for new log records.
The default value is |
|||||||||||||||||||||||||||||||||||||
This boolean directive instructs the module on where to start reading events from the log source when NXLog Agent starts. When When The default is The following matrix shows the outcome of this directive in conjunction with the SavePos directive:
If the NoCache directive is |
|||||||||||||||||||||||||||||||||||||
Set this directive to
|
|||||||||||||||||||||||||||||||||||||
Set this directive to The default is If the NoCache directive is |
|||||||||||||||||||||||||||||||||||||
Set this directive to filter which log records the module collects, using the |
Fields
The following fields are created by im_macoslog.
-
$raw_event(type: string) -
A list of event fields in key-value pairs.
-
$activityIdentifier(type: string) -
A numeric ID for an activity.
-
$category(type: string) -
The category of the event.
-
$eventMessage(type: string) -
The message associated with the event.
-
$EventTime(type: datetime) -
The timestamp of the event.
-
$eventType(type: string) -
The type of event. For this module, the value is
eventLog. -
$formatString(type: string) -
The format string used to form
eventMessage. -
$GID(type: integer) -
The group identifier associated with the
$processIDwhen the module collects the event. See the ResolveUserGroup directive for more information. -
$groupName(type: string) -
If ResolveUserGroup is
TRUEand the name is successfully resolved, this field contains the group name associated with the$GID. -
$processID(type: integer) -
The ID of the process that logged the event.
-
$processName(type: string) -
The name of the process that logged the event.
-
$Severity(type: string) -
The log level of the event. The possible values are
Undefined,Debug,Info,Notice,Error, orFault. -
$subsystem(type: string) -
The subsystem used to log the event.
-
$threadID(type: string) -
The ID of the thread that logged the event.
-
$UID(type: integer) -
The user identifier associated with the
$processIDwhen the module collects the event. See the ResolveUserGroup directive for more information. -
$userName(type: string) -
If ResolveUserGroup is
TRUEand the name is successfully resolved, this field contains the user name associated with the$UID.
Examples
This configuration collects all records logged after the module’s first start.
<Input macoslog>
Module im_macoslog
</Input>
This configuration uses Source to collect only records from the com.apple.securityd subsystem and any subsystem’s connection category, then uses MinLevel to drop anything less severe than Notice.
<Input macoslog>
Module im_macoslog
Source com.apple.securityd/*
Source */connection
MinLevel Notice
</Input>
This configuration sets ReadFromLast to FALSE to read all available records on the module’s first start.
It also increases Lag to tolerate a 2-second ingestion lag, and turns on ResolveUserGroup to populate the userName and groupName fields.
<Input macoslog>
Module im_macoslog
ReadFromLast FALSE
Lag 2
ResolveUserGroup TRUE
</Input>