Getting Data In

Getting Events from MAC OS

Path Finder

I'm a Windows guy working with Linux trying to get MAC OS events into Splunk.  We don't have many MACs where I work, but we do have some.  Does anyone have reference material on the inputs.conf for MAC OSs and how I get the events into Splunk?  The Splunk UF is installed, but I need to know more about what to monitor on MAC OSs.


Labels (1)
Tags (3)
0 Karma


Unfortunately there is no good native way to do it after Apple changed it's logging framework without any external programs/utils.

Here is some like which you could look:

Of course you must 1st know what you want to log from those nodes.

If those logs which you are interested are normal file based logs then collect those as any other logs in unix platforms.

r. Ismo

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!