Monitoring Splunk

Inserting mac os event logs in splunk

pulen
New Member

I am really struggling to add my macos data into splunk just like how we can upload the event logs of windows. is there any add-ons that i can install to help me do this? if there is, can anyone explain how to configure it and make it work? 

Labels (1)
0 Karma

deepakc
Builder

To get you started here's a number of links for you read and work through

In short you need the nix TA, UF and configure inputs and outputs based on your requirements.

#This shows you the TA Required (Nix TA)
https://splunkbase.splunk.com/app/833


#This shows you the OS Supported = MacOs is listed
https://docs.splunk.com/Documentation/AddOns/latest/UnixLinux/About

 

#Read the release notes
https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Releasenotes

And you will need to install a Universal Forwarder for the MacOS + configure outputs and TA inputs
https://www.splunk.com/en_us/download/universal-forwarder.html

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...