<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mac OS X  Sierra - How to get all logs from the Unified Log database? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347709#M95993</link>
    <description>&lt;P&gt;One other rabbit hole I went down to get audit log data is using auditreduce + praudit&lt;/P&gt;

&lt;P&gt;Again this works - audit data goes to splunk - but produces mostly noise.  It checks a compliance box without being particularly useful.&lt;/P&gt;

&lt;P&gt;I'll check out xnumon.  Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jul 2018 17:01:23 GMT</pubDate>
    <dc:creator>bgstein</dc:creator>
    <dc:date>2018-07-12T17:01:23Z</dc:date>
    <item>
      <title>Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347695#M95979</link>
      <description>&lt;P&gt;Couldn't find a similar question to this one. How are people retrieving logs from Mac OS X Sierra that are in the Unified Logging Database? This was a new logging technology released with Sierra (think it's stored in a binary database). It has way better and more detailed logs compared to the deprecated system.log file. There is practically nothing going to the system.log file in newer OS X versions... Ideally, I'd like to output data from the database and append it to the system.log file so it can get picked up with the rest of our old fashioned syslog (and be forwarded by using an old fashioned forwarding server over udp:514.) The asl.conf appears to be superseded by the Unified Logging as well. Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 15:24:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347695#M95979</guid>
      <dc:creator>managed_securit</dc:creator>
      <dc:date>2017-06-15T15:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347696#M95980</link>
      <description>&lt;P&gt;some docs from macos&lt;BR /&gt;
&lt;A href="https://www.mac4n6.com/blog/2016/11/13/new-macos-sierra-1012-forensic-artifacts-introducing-unified-logging"&gt;https://www.mac4n6.com/blog/2016/11/13/new-macos-sierra-1012-forensic-artifacts-introducing-unified-logging&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You could create scripted or modular inputs to run the "log show" command and ingest the events.&lt;BR /&gt;
The difficulty will be :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;to decide if you want a live tailing, or a backlog collection of the logs.&lt;/LI&gt;
&lt;LI&gt;to specify and maintain a position checkpoint to avoid reindexing the same events over and over.
A modular input may be more appropriate.
see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.0/AdvancedDev/ModInputsIntro"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.0/AdvancedDev/ModInputsIntro&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 17 Jul 2017 19:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347696#M95980</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2017-07-17T19:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347697#M95981</link>
      <description>&lt;P&gt;I was afraid this might be the answer. In our current case we prefer to have real-time logs so that we could use some alerting. Having a script running a tail on the logs output is not ideal, but something I had thought of.&lt;/P&gt;

&lt;P&gt;I'm reading your info on modular inputs, but it's a little confusing. I don't see a difference between using that vs a shell script.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 14:27:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347697#M95981</guid>
      <dc:creator>managed_securit</dc:creator>
      <dc:date>2017-07-18T14:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347698#M95982</link>
      <description>&lt;P&gt;@yannK, when do you think Splunk will get built-in support for ingesting logs from OS X Sierra and above?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 07:52:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347698#M95982</guid>
      <dc:creator>johanwalles</dc:creator>
      <dc:date>2017-08-17T07:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347699#M95983</link>
      <description>&lt;P&gt;Hi managed_security what did you end up setting up? Any chance that you could share a modular input if you set on up?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 12:20:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347699#M95983</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2017-10-02T12:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347700#M95984</link>
      <description>&lt;P&gt;For anyone else stumbling accross this question: Splunk has an open enhancement request for this: SPL-129734. If this is something you need opening a case with a reference to this question might accelerate the implementation.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 07:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347700#M95984</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2017-10-04T07:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347701#M95985</link>
      <description>&lt;P&gt;I'm in the same boat.  Need to send/ingest the unified logs from 10.12+ clients.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 02:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347701#M95985</guid>
      <dc:creator>toyboxent</dc:creator>
      <dc:date>2017-10-14T02:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347702#M95986</link>
      <description>&lt;P&gt;So are we in a state where basically Splunk does not work with newer OS/X versions, with the new logging system?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 23:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347702#M95986</guid>
      <dc:creator>rgoerwit</dc:creator>
      <dc:date>2017-11-30T23:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347703#M95987</link>
      <description>&lt;P&gt;The Splunkforwarder can be installed and configured  to index information from unified logging. There is just no out of the box functionality for that. &lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 07:20:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347703#M95987</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2017-12-04T07:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347704#M95988</link>
      <description>&lt;P&gt;Please provide step-by-step guidance to on how to get logs from Sierra to Splunk&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 19:39:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347704#M95988</guid>
      <dc:creator>MRSTANG</dc:creator>
      <dc:date>2017-12-20T19:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347705#M95989</link>
      <description>&lt;P&gt;It is probably best to contact Splunk, if you need the data from unified logging. That way they can push SPL-129734 internally. For now we rely on some scripts from the Unix TA, I have heard that others use &lt;A href="https://osquery.io/"&gt;https://osquery.io/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 11:57:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347705#M95989</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2017-12-21T11:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347706#M95990</link>
      <description>&lt;P&gt;One possibility is to use osquery to pull the data from asl and put it into a file monitored by the splunk forwarder.  And of course osquery exposes lots of other stuff you could grab too.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://medium.com/@clong/osquery-for-security-b66fffdf2daf"&gt;https://medium.com/@clong/osquery-for-security-b66fffdf2daf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://blog.kolide.com/monitoring-macos-hosts-with-osquery-ba5dcc83122d"&gt;https://blog.kolide.com/monitoring-macos-hosts-with-osquery-ba5dcc83122d&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This works - the part I'm struggling with is figuring out what to grab.  &lt;/P&gt;

&lt;P&gt;Working with the log command in Sierra lets you play with the logged data but I don't see any guidance or recommendations on what to grab to meet standard audit requirements.  If you can grab everything great - but if you are concerned about license capacity then most of the stuff going to asl looks like noise and should be filtered at the host.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jul 2018 22:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347706#M95990</guid>
      <dc:creator>bgstein</dc:creator>
      <dc:date>2018-07-06T22:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347707#M95991</link>
      <description>&lt;P&gt;&lt;A href="https://github.com/droe/xnumon"&gt;https://github.com/droe/xnumon&lt;/A&gt; might also help it's "sysmon for macos"&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 06:02:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347707#M95991</guid>
      <dc:creator>chris</dc:creator>
      <dc:date>2018-07-09T06:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347708#M95992</link>
      <description>&lt;P&gt;Bumping xnumon as a pretty complete solution to this problem. You'll need to transform the input to be CIM compliant since there is not an app available at the time but out of the box it's a fairly on par with what sysmon offers. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 15:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347708#M95992</guid>
      <dc:creator>dhaynes_</dc:creator>
      <dc:date>2018-07-12T15:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347709#M95993</link>
      <description>&lt;P&gt;One other rabbit hole I went down to get audit log data is using auditreduce + praudit&lt;/P&gt;

&lt;P&gt;Again this works - audit data goes to splunk - but produces mostly noise.  It checks a compliance box without being particularly useful.&lt;/P&gt;

&lt;P&gt;I'll check out xnumon.  Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 17:01:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347709#M95993</guid>
      <dc:creator>bgstein</dc:creator>
      <dc:date>2018-07-12T17:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347710#M95994</link>
      <description>&lt;P&gt;I'd be very happy to add a sample Splunk config for CIM compliant field extraction to xnumon, feel free to submit one on Github in an issue or pull request.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 21:03:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347710#M95994</guid>
      <dc:creator>droe</dc:creator>
      <dc:date>2018-07-19T21:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347711#M95995</link>
      <description>&lt;P&gt;I ended up kludging a pretty generic scripted input that.&lt;/P&gt;

&lt;P&gt;Runs the log show command from start_date to end_date. &lt;BR /&gt;
Greps what you want using an include file.&lt;BR /&gt;
Greps out stuff with an exclude file.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://community.splunk.com/storage/temp/271087-uf-macintoshtar.zip" target="_blank"&gt;tar-zipped TA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347711#M95995</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2020-09-30T00:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347712#M95996</link>
      <description>&lt;P&gt;Thanks for posting. How did you managed to deal with "log show" permissions? Is there any other way than putting user "splunk" into the admin group?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;dseditgroup -o edit -a splunk -t user admin
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Mar 2020 13:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347712#M95996</guid>
      <dc:creator>MaverickT</dc:creator>
      <dc:date>2020-03-23T13:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347713#M95997</link>
      <description>&lt;P&gt;I don't currently have a mac to test with and I'm not a Mac guy but something like this might work.&lt;/P&gt;

&lt;P&gt;Add this to /etc/sudoers to permit the splunk user to run log without a password.&lt;BR /&gt;
splunk ALL = NOPASSWD: &lt;STRONG&gt;/path/to/log&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Edit the uf_macintosh/bin/mac_log_monitor.sh and add &lt;STRONG&gt;sudo&lt;/STRONG&gt; to the command.&lt;/P&gt;

&lt;P&gt;FROM&lt;BR /&gt;
log show --style syslog --start "$START_DATE" --end "$END_DATE" | egrep -f $INCLUDE | egrep -vf $EXCLUDE&lt;/P&gt;

&lt;P&gt;TO &lt;BR /&gt;
&lt;STRONG&gt;sudo /path/to/log&lt;/STRONG&gt; show --style syslog --start "$START_DATE" --end "$END_DATE" | egrep -f $INCLUDE | egrep -vf $EXCLUDE&lt;/P&gt;

&lt;P&gt;Let me know how it goes!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:45:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347713#M95997</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2020-09-30T04:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS X  Sierra - How to get all logs from the Unified Log database?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347714#M95998</link>
      <description>&lt;P&gt;Thanks for the quick response and advice. I had to modify config entry a little, but not much.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk ALL=(ALL) NOPASSWD: /usr/bin/log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Just the thing I've noticed. In case the "log show" is not allowed to be run or some other exception happens, the script still updates the last_run_date.txt file. I am thinking of modifying the script so it would update the last_run_date.txt file after log show command would be successfully run.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Mac-OS-X-Sierra-How-to-get-all-logs-from-the-Unified-Log/m-p/347714#M95998</guid>
      <dc:creator>MaverickT</dc:creator>
      <dc:date>2020-09-30T04:45:07Z</dc:date>
    </item>
  </channel>
</rss>

