macOS Unified Logs
Also called unified logging, tracev3, log show, Apple System Log successor.
- PLATFORM
- macOS
- CATEGORY
- Program Execution
- INDEX
- 21 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
The macOS system-wide log stream, recording process launches, device attachment, authentication and application behaviour in extraordinary detail for a short period.
Where it lives
/private/var/db/diagnostics/ with string catalogues in /private/var/db/uuidtext/
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of macos unified logs” is neither.
What it records
Unified logging captures messages emitted by the system and by applications, each carrying a subsystem and category, a process, an activity identifier and a high-resolution timestamp, stored in a compressed binary format alongside separate string catalogues that supply the message templates. Coverage is broad — device attachment, mount events, authentication, network configuration, application errors — and the volume is correspondingly enormous, which is why retention is short. Message fields marked private are redacted unless a configuration profile enabled their capture.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- Precise, high-resolution timing of system events including device attachment, mounts, unlocks and process activity
- Correlation across subsystems, since related messages share an activity identifier
- Behaviour of specific applications, including errors and connection attempts that appear in no other artifact
- The presence of an external device and the volume it presented, corroborating other removable-media evidence on a platform where registry equivalents do not exist
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- Anything about the period before the logs rolled. Retention is a function of message volume and commonly amounts to days or a few weeks, which is short relative to the age of most civil disputes
- The content of redacted fields. Values marked private are replaced in the stored record, and no examination recovers what was never written
- Consistent availability of any particular message. Subsystems, categories and message text change between macOS releases, so a message relied on for one version may not exist on another
- User attribution for system-level messages, many of which are emitted by daemons with no association to a logged-in account
- That an event did not occur because no message appears. Logging level is configurable per subsystem and much activity is never emitted at all
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Establishing the earliest surviving message and showing the relevant period is not covered
- Pointing to private-field redaction where the examiner's conclusion depends on a value that was never stored
- Questioning message interpretation, since much of the stream is undocumented internal telemetry rather than a specified evidentiary record
- Showing that the acquisition did not capture the string catalogues, without which messages cannot be reconstructed reliably
What survives, and for how long
The archive rolls continuously as new messages arrive, so coverage is measured in days to a few weeks on an active machine and less on a busy one. Nothing about it is designed for retention, and a Mac imaged a month after the conduct usually holds no unified log evidence of it at all.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
How long do macOS unified logs keep data?
Days to a few weeks on a typical machine, and less on a busy one, because retention is governed by message volume rather than by a fixed period. The system rolls old archives continuously. In practice this means unified logs are only available when a Mac is preserved quickly, and their absence in a matter preserved months later says nothing about what happened.
Can unified logs show a USB device was connected to a Mac?
Yes, where the logs still cover the period. Device attachment, driver matching and volume mount messages appear in the stream with high-resolution timestamps, which matters on macOS because there is no registry equivalent of the Windows device enumeration keys. It is the timing source that anchors other macOS device evidence such as the volume's own FSEvents log.
What does <private> mean in a macOS log entry?
It marks a field the logging system redacted at the point of writing, so the value was never stored. It is not encryption and it is not recoverable by examination. Capture of those fields requires a configuration profile installed before the events occurred, which in civil matters it almost never is. An opinion that depends on a redacted value cannot be supported from the logs.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
KnowledgeC
A macOS database of user-activity streams recording which applications were in focus and for how long, when the display was lit, and when the device was locked.
FSEvents
A per-volume macOS log of directory-level change notifications recording that paths were created, renamed, modified or removed — ordered by event identifier rather than by clock time.
LSQuarantine
A per-user macOS database recording files downloaded by quarantine-aware applications, with the source URL, the downloading application, and a timestamp for each event.
USB Connection Event Logs
Event-log channels that timestamp individual device arrivals and removals, and which — unlike the registry — can record how often a device was connected and how large its volume was.
Whether the macos unified logsevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.