Skip to content

LogsExecutionNetwork

System Logs: macOS /var/log Text and ASL Files

The flat log files that survive on macOS (install.log, system.log, wifi.log, ASL stores) and how syslogd, aslmanager and newsyslog rotate them.

Location
/private/var/log/
Proves
Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retention
Timestamps
Local time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no year
Access
admin group or root (system.log and wifi.log are mode 640, group admin)
Retention
Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/
Collection
UAC, Aftermath, sysdiagnose, ditto

What it is

Before macOS 10.12 Sierra, most system activity went to text files in /var/log through syslogd and the Apple System Log (ASL). Sierra moved almost everything to the Unified Logs, but syslogd still runs and a handful of text and ASL logs are still written. Some of them, notably install.log, keep months of history on a quiet machine, far longer than the Unified Log store.

Three mechanisms decide what is written and how long it survives: syslogd rules in /etc/asl.conf and /etc/asl/*, aslmanager which rotates and expires those outputs, and newsyslog (run hourly by launchd) for files listed in /etc/newsyslog.conf and /etc/newsyslog.d/*.conf.

Where it lives

FileWritten by / rotation configNotes
/private/var/log/install.log/etc/asl/com.apple.install: file_max=50M all_max=150MInstaller, softwareupdated, installd, App Store, XProtect updates
/private/var/log/system.log (+ .N.gz)/etc/asl.conf: file_max=5M all_max=50M, rotate=seq compressSparse since Sierra: legacy syslog() callers only
/private/var/log/wifi.log (+ .N.bz2)/etc/newsyslog.d/wifi.conf: daily at midnight, 10 archivesPresent on 26 Tahoe
/private/var/log/appfirewall.log/etc/asl.conf rule for com.apple.alf.loggingWhen the application firewall logs
/private/var/log/asl/*.aslASL data store, aslmanagerBinary; default time-to-live 7 days
/private/var/log/DiagnosticMessages//etc/asl/com.apple.MessageTracer, ttl=30ASL store of MessageTracer events
/private/var/log/fsck_apfs.log, fsck_hfs.logWritten by fsck toolsVolume checks, including external disks
/private/var/log/shutdown_monitor.log, powermanagement/System servicesShutdown and power history
/private/var/log/daily.out, weekly.out, monthly.outperiodicUp to 14 Sonoma only; see cron and periodic
/private/var/log/asl.db, asl.logOld ASL formatsOnly on very old releases (asl.log 10.4, asl.db 10.5)
/Library/Logs/, ~/Library/Logs/Apps and system componentsIncludes DiagnosticReports, see crash reports

On current releases system.log and wifi.log are root:admin mode 640 and install.log is world-readable, so admin users can read most of them without sudo.

What it proves

  • install.log: which packages and updates were installed, by which process, with the package path and result, and user-facing Installer sessions.
  • wifi.log: Wi-Fi association, scanning and roaming, useful with Wi-Fi networks.
  • system.log: activity by processes that still use the legacy syslog() API, and syslogd checkpoint events. On 10.11 and earlier it is the main log, including sudo (see sudo logs).
  • fsck_* logs: which volumes were checked and when, including removable media.

These files are a subset of system activity. Their silence on a topic says little; check the Unified Logs.

Key fields

Line layout depends on the configured format:

FileLayout
install.log (current format)2026-09-29 10:46:07+02 <host> <sender>[<pid>]: <message> from the rule $((Time)(JZ)) $Host $(Sender)[$(PID)]: $Message
system.log (BSD style)Sep 29 11:34:02 <host> <sender>[<pid>]: <message>
wifi.log (airportd's own format, most lines)Tue Sep 29 00:30:32.447 [<component>] ... with milliseconds, no year and no zone
ASL .asl recordsKeys such as Time, TimeNanoSec, Host, Sender, PID, UID, GID, Level, Facility, Message

Useful install.log senders: Installer (GUI, logs Opened from: <path>.pkg), installer (command line), installd, system_installd, package_script_service (pre/postinstall scripts), softwareupdated, appstoreagent.

Timestamps

  • install.log lines written with the current format carry local time plus UTC offset (+02). The same file can also contain BSD-style lines without year or offset from other writers; do not assume one format per file.
  • BSD syslog lines and wifi.log lines have no year and no zone. Infer the year from rotation file names and file times, and the zone from the system settings at the time.
  • ASL records store Time as Unix epoch seconds plus TimeNanoSec.
syslog -f /private/var/log/asl/2026.09.28.G80.asl -F '$((Time)(utc)) $Sender[$PID] $Message'

Retention

  • aslmanager rotates asl.conf outputs by size (file_max) and deletes the oldest rotated copies when the total exceeds all_max; ttl=DAYS on a rule deletes rotated files older than that.
  • The ASL data store defaults to a 7-day time-to-live and a 150,000,000-byte cap (store_ttl, max_store_size in asl.conf).
  • newsyslog rotates wifi.log daily ($D0) and keeps 10 bzip2 archives (J flag).
  • install.log rotation is size-only (size_only), so it often holds many months of history.

Deleting or truncating these files needs root. A missing install.log or a sequence gap in rotated names (system.log.0.gz, .1.gz, ...) is worth explaining.

Collection

sudo ditto /private/var/log ./case/var_log
sudo ditto /private/etc/asl.conf /private/etc/asl /private/etc/newsyslog.conf \
           /private/etc/newsyslog.d ./case/log_config/
  • UAC collects /private/var/log (files/logs/var_log.yaml), ASL stores, /Library/Logs and user ~/Library/Logs.
  • Aftermath copies install.log, system.log, wifi.log, appfirewall.log, fsck_* logs and /var/log/asl/, and parses install.log and system.log in --analyze.
  • sysdiagnose includes many of these files.
  • Dead-box: copy from /System/Volumes/Data/private/var/log on the mounted image.

Parsing

  • grep / zgrep / bzgrep on text logs and rotated archives:
zgrep -h 'installd\|softwareupdated' install.log* | sort | less
bzgrep -h '<network name>' wifi.log wifi.log.*.bz2
  • syslog -f for .asl files on a Mac.
  • Plaso: asl_log (ASL files), text/mac_wifi, text/mac_appfirewall_log, text/syslog: log2timeline.py --parsers 'asl_log,text/mac_wifi,text/syslog' --storage-file logs.plaso ./case/var_log.
  • mac_apt ASL plugin reads asl.log, asl.db, *.asl and powermanagement data.

Investigator tips

  • On any post-Sierra Mac, start with install.log: it often reaches further back than any other log and records unsigned or third-party packages next to Apple updates. Correlate with install history.
  • install.log records Opened from: with the package path for Installer sessions, which can reveal a download folder or mounted image that no longer exists, and package_script_service lines show what install scripts did.
  • Read /etc/asl.conf, /etc/asl/* and /etc/newsyslog.d/* from the evidence, not from your analysis Mac: an attacker or admin can shorten retention or disable a file there.
  • Rotated archives are compressed (.gz for ASL-managed files, .bz2 for newsyslog J entries); include them in searches.
  • wifi.log on current releases is a good second source for network location history when the Unified Logs have rotated.
  • Legacy sudo and login evidence lives in system.log only on 10.11 and earlier images.

See also