Monitoring Splunk

Would like to build basic dashboards showing graphs based on the contents of monitored logs on macOS


However, so far, I can't derive anything meaningful for building the dashboards.

I would like to set Splunk to monitor the host operating systems logs files and/or performance data on macOS. I get data in from sources including '/var/log' and '/Library/Logs' but don't see anything meaningful from the data with certain field values filtered. I would also like to monitor the performance data but not sure where they locate at or how to filter the values. Any help would be appreciated! Thanks!

  • System Log Folder: /var/log
  • System Log: /var/log/system.log
  • Mac Analytics Data: /var/log/DiagnosticMessages
  • System Application Logs: /Library/Logs
  • System Reports: /Library/Logs/DiagnosticReports
  • User Application Logs: ~/Library/Logs (in other words, /Users/NAME/Library/Logs)
  • User Reports: ~/Library/Logs/DiagnosticReports (in other words, /Users/NAME/Library/Logs/DiagnosticReports)
Labels (1)
0 Karma


Is the below page what I am supposed to follow? However, I can't find the OSX after clicking 'Add Data'

For performance data, I assume I should monitor the cpu, ram, battery usage, etc. for creating meaningful dashboards? However, are there any logs for this performance data on macOS? If not, how should I get this data in from maybe Activity Monitor? Thanks!

0 Karma

Tune In & Win!

Don't miss out on your
chance to take home free
prizes by helping our players
save the Splunk Cloudom!

Dungeons & Data
Monsters: Splunk O11y
Day Editions Games
stream live:
5/4 at 6:30pm PST
5/5 at 7:00pm PST