<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mac OS client logs into splunk in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246294#M3816</link>
    <description>&lt;P&gt;I have posted some MacOS configuration info here &lt;A href="https://patent-ed.com/category/os/splunk/"&gt;https://patent-ed.com/category/os/splunk/&lt;/A&gt;  - I also know CMDSecurity has an app to help with this and more &lt;A href="https://www.cmdsec.com/cmdreporter/"&gt;https://www.cmdsec.com/cmdreporter/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2019 10:04:10 GMT</pubDate>
    <dc:creator>eredux</dc:creator>
    <dc:date>2019-09-16T10:04:10Z</dc:date>
    <item>
      <title>Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246286#M3808</link>
      <description>&lt;P&gt;I'm tasked with getting our Mac OS clients (desktops and laptops) to log the following to splunk:&lt;/P&gt;
&lt;P&gt;Authentication success&lt;BR /&gt;Authentication failures&lt;BR /&gt;Invalid login&lt;BR /&gt;Adding/removing user accounts&lt;BR /&gt;User Account Modification&lt;BR /&gt;Installation of software&lt;BR /&gt;Modification of relevant configuration, such as firewall, logs etc&lt;/P&gt;
&lt;P&gt;I can't find any configuration docs for getting these types of logs from OS X -&amp;gt; splunk.&lt;BR /&gt;After reading a couple of the answers here I also found that noone seems to have had any problems with it or at least not asked any questions about it, besides that the asl(syslog)-files in OS X now is binary and hence not read by the universal forwarder.&lt;/P&gt;
&lt;P&gt;Am I really the first one to wonder how this should be done?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 16:11:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246286#M3808</guid>
      <dc:creator>jbygden</dc:creator>
      <dc:date>2020-06-06T16:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246287#M3809</link>
      <description>&lt;P&gt;I share your pain...  Did you make progress with this?&lt;/P&gt;

&lt;P&gt;There is an old document that doesn't seem to work for current versions of Mac OS X:&lt;BR /&gt;
&lt;A href="https://wiki.splunk.com/Community:HowTo_Configure_Mac_OS_X_Syslog_To_Forward_Data"&gt;https://wiki.splunk.com/Community:HowTo_Configure_Mac_OS_X_Syslog_To_Forward_Data&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 18:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246287#M3809</guid>
      <dc:creator>bgstein</dc:creator>
      <dc:date>2017-04-14T18:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246288#M3810</link>
      <description>&lt;P&gt;A similar discussion is here. Not sure how useful it is.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://community.spiceworks.com/topic/562291-how-to-audit-log-file-access-events-on-mac-os-x"&gt;https://community.spiceworks.com/topic/562291-how-to-audit-log-file-access-events-on-mac-os-x&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 20:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246288#M3810</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-04-14T20:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246289#M3811</link>
      <description>&lt;P&gt;After having created a support case with splunk and chatting with an employee I've deployed the downloadable pkg to some of my Macs and it seems to work pretty good.&lt;/P&gt;

&lt;P&gt;Be aware of the applescripts that make assumptions that's probably not relevant for anyone though.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2017 22:02:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246289#M3811</guid>
      <dc:creator>jbygden</dc:creator>
      <dc:date>2017-04-14T22:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246290#M3812</link>
      <description>&lt;P&gt;I would greatly appreciate finding out more about this said package? please. Can you share your contact at Splunk with me?  &lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 18:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246290#M3812</guid>
      <dc:creator>eredux</dc:creator>
      <dc:date>2017-08-31T18:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246291#M3813</link>
      <description>&lt;P&gt;Apparently he's not with splunk anymore...&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 07:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246291#M3813</guid>
      <dc:creator>jbygden</dc:creator>
      <dc:date>2017-09-01T07:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246292#M3814</link>
      <description>&lt;P&gt;I think they just used the Universal Forwarder. The first line of the install instructions says this.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.6.3/Forwarder/Installanixuniversalforwarder#Install_the_universal_forwarder_on_Mac_OS_X"&gt;Double-click on the DMG file. A Finder window that contains splunkforwarder.pkg opens.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2017 15:57:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246292#M3814</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2017-09-19T15:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246293#M3815</link>
      <description>&lt;P&gt;Has anybody found a solution on how to get Mac OS client logs into splunk ?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 23:33:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246293#M3815</guid>
      <dc:creator>Greendav</dc:creator>
      <dc:date>2019-09-15T23:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246294#M3816</link>
      <description>&lt;P&gt;I have posted some MacOS configuration info here &lt;A href="https://patent-ed.com/category/os/splunk/"&gt;https://patent-ed.com/category/os/splunk/&lt;/A&gt;  - I also know CMDSecurity has an app to help with this and more &lt;A href="https://www.cmdsec.com/cmdreporter/"&gt;https://www.cmdsec.com/cmdreporter/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 10:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246294#M3816</guid>
      <dc:creator>eredux</dc:creator>
      <dc:date>2019-09-16T10:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OS client logs into splunk</title>
      <link>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246295#M3817</link>
      <description>&lt;P&gt;Once you install the UF, you can use this simplistic script I wrote that pulls the logs I needed. It just uses the "log show" command to dump the logs and then greps out the stuff in the include file. &lt;STRONG&gt;Note&lt;/STRONG&gt;: "log show" requires admin.&lt;/P&gt;

&lt;P&gt;My answer here has a tar file that contains the script.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/547865/mac-os-x-sierra-how-to-get-all-logs-from-the-unifi.html"&gt;https://answers.splunk.com/answers/547865/mac-os-x-sierra-how-to-get-all-logs-from-the-unifi.html&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#!/bin/bash
# Usage: ./mac_log_monitor.sh
# Runs the Macintosh log show command to get Macintosh user logs from START_DATE to END_DATE.

DATE_PATH=$SPLUNK_DB/persistentstorage/uf_macintosh   # Setup the date file.
DATE_FILE=$SPLUNK_DB/persistentstorage/uf_macintosh/last_run_date.txt   # Setup the date file.
if [ ! -e "$DATE_FILE" ]                # Does the date file exist.
then                            # No. date file does not exist.
  if [ ! -e "$DATE_PATH" ]
  then
    mkdir $DATE_PATH
  fi
  date -v -1w +"%F %T" &amp;gt; $DATE_FILE         # Set start date to -1 week to get old logs. Redeploying overwrites this.
fi

START_DATE=`cat $DATE_FILE`             # Set start date for log reading.
date +"%F %T" &amp;gt; $DATE_FILE              # Set new start date for next run. 
END_DATE=`cat $DATE_FILE`               # Set end date for log reading.

# File with keywords to grep from logs.
INCLUDE=$SPLUNK_ETC/apps/uf_macintosh/local/include.conf

# File with keywords to exclude from logs.
EXCLUDE=$SPLUNK_ETC/apps/uf_macintosh/local/exclude.conf

# Macintosh log command. Need to figure out predicaate so we can pull the logs we need instead of everything.
#log show --predicate [] --style syslog --start [] --end [] --info --last []

# Should really have an if to check for the existance of include/exclude
log show --style syslog --start "$START_DATE" --end "$END_DATE" | egrep -f $INCLUDE | egrep -vf $EXCLUDE
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 16 Sep 2019 11:20:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Mac-OS-client-logs-into-splunk/m-p/246295#M3817</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2019-09-16T11:20:59Z</dc:date>
    </item>
  </channel>
</rss>

