System Logs: macOS /var/log Text and ASL Files
The flat log files that survive on macOS (install.log, system.log, wifi.log, ASL stores) and how syslogd, aslmanager and newsyslog rotate them.
- Location
- /private/var/log/
- Proves
- Install, update, Wi-Fi and legacy syslog activity, often beyond Unified Log retention
- Timestamps
- Local time; install.log uses ISO-style time with UTC offset, BSD syslog lines have no year
- Access
- admin group or root (system.log and wifi.log are mode 640, group admin)
- Retention
- Size or daily rotation set in /etc/asl.conf, /etc/asl/ and /etc/newsyslog.d/
- Collection
- UAC, Aftermath, sysdiagnose, ditto
Tools
Compare all tools- PlasoCLI · open source
- mac_aptCLI · open source
- syslogCLI · built into macOS
- grepCLI · built into macOS
What it is
Before macOS 10.12 Sierra, most system activity went to text files in /var/log through syslogd and the Apple System Log (ASL). Sierra moved almost everything to the Unified Logs, but syslogd still runs and a handful of text and ASL logs are still written. Some of them, notably install.log, keep months of history on a quiet machine, far longer than the Unified Log store.
Three mechanisms decide what is written and how long it survives: syslogd rules in /etc/asl.conf and /etc/asl/*, aslmanager which rotates and expires those outputs, and newsyslog (run hourly by launchd) for files listed in /etc/newsyslog.conf and /etc/newsyslog.d/*.conf.
Where it lives
| File | Written by / rotation config | Notes |
|---|---|---|
/private/var/log/install.log | /etc/asl/com.apple.install: file_max=50M all_max=150M | Installer, softwareupdated, installd, App Store, XProtect updates |
/private/var/log/system.log (+ .N.gz) | /etc/asl.conf: file_max=5M all_max=50M, rotate=seq compress | Sparse since Sierra: legacy syslog() callers only |
/private/var/log/wifi.log (+ .N.bz2) | /etc/newsyslog.d/wifi.conf: daily at midnight, 10 archives | Present on 26 Tahoe |
/private/var/log/appfirewall.log | /etc/asl.conf rule for com.apple.alf.logging | When the application firewall logs |
/private/var/log/asl/*.asl | ASL data store, aslmanager | Binary; default time-to-live 7 days |
/private/var/log/DiagnosticMessages/ | /etc/asl/com.apple.MessageTracer, ttl=30 | ASL store of MessageTracer events |
/private/var/log/fsck_apfs.log, fsck_hfs.log | Written by fsck tools | Volume checks, including external disks |
/private/var/log/shutdown_monitor.log, powermanagement/ | System services | Shutdown and power history |
/private/var/log/daily.out, weekly.out, monthly.out | periodic | Up to 14 Sonoma only; see cron and periodic |
/private/var/log/asl.db, asl.log | Old ASL formats | Only on very old releases (asl.log 10.4, asl.db 10.5) |
/Library/Logs/, ~/Library/Logs/ | Apps and system components | Includes DiagnosticReports, see crash reports |
On current releases system.log and wifi.log are root:admin mode 640 and install.log is world-readable, so admin users can read most of them without sudo.
What it proves
install.log: which packages and updates were installed, by which process, with the package path and result, and user-facing Installer sessions.wifi.log: Wi-Fi association, scanning and roaming, useful with Wi-Fi networks.system.log: activity by processes that still use the legacysyslog()API, andsyslogdcheckpoint events. On 10.11 and earlier it is the main log, includingsudo(see sudo logs).fsck_*logs: which volumes were checked and when, including removable media.
These files are a subset of system activity. Their silence on a topic says little; check the Unified Logs.
Key fields
Line layout depends on the configured format:
| File | Layout |
|---|---|
install.log (current format) | 2026-09-29 10:46:07+02 <host> <sender>[<pid>]: <message> from the rule $((Time)(JZ)) $Host $(Sender)[$(PID)]: $Message |
system.log (BSD style) | Sep 29 11:34:02 <host> <sender>[<pid>]: <message> |
wifi.log (airportd's own format, most lines) | Tue Sep 29 00:30:32.447 [<component>] ... with milliseconds, no year and no zone |
ASL .asl records | Keys such as Time, TimeNanoSec, Host, Sender, PID, UID, GID, Level, Facility, Message |
Useful install.log senders: Installer (GUI, logs Opened from: <path>.pkg), installer (command line), installd, system_installd, package_script_service (pre/postinstall scripts), softwareupdated, appstoreagent.
Timestamps
install.loglines written with the current format carry local time plus UTC offset (+02). The same file can also contain BSD-style lines without year or offset from other writers; do not assume one format per file.- BSD syslog lines and
wifi.loglines have no year and no zone. Infer the year from rotation file names and file times, and the zone from the system settings at the time. - ASL records store
Timeas Unix epoch seconds plusTimeNanoSec.
syslog -f /private/var/log/asl/2026.09.28.G80.asl -F '$((Time)(utc)) $Sender[$PID] $Message'
Retention
aslmanagerrotatesasl.confoutputs by size (file_max) and deletes the oldest rotated copies when the total exceedsall_max;ttl=DAYSon a rule deletes rotated files older than that.- The ASL data store defaults to a 7-day time-to-live and a 150,000,000-byte cap (
store_ttl,max_store_sizeinasl.conf). newsyslogrotateswifi.logdaily ($D0) and keeps 10 bzip2 archives (Jflag).install.logrotation is size-only (size_only), so it often holds many months of history.
Deleting or truncating these files needs root. A missing install.log or a sequence gap in rotated names (system.log.0.gz, .1.gz, ...) is worth explaining.
Collection
sudo ditto /private/var/log ./case/var_log
sudo ditto /private/etc/asl.conf /private/etc/asl /private/etc/newsyslog.conf \
/private/etc/newsyslog.d ./case/log_config/
- UAC collects
/private/var/log(files/logs/var_log.yaml), ASL stores,/Library/Logsand user~/Library/Logs. - Aftermath copies
install.log,system.log,wifi.log,appfirewall.log,fsck_*logs and/var/log/asl/, and parsesinstall.logandsystem.login--analyze. - sysdiagnose includes many of these files.
- Dead-box: copy from
/System/Volumes/Data/private/var/logon the mounted image.
Parsing
- grep / zgrep / bzgrep on text logs and rotated archives:
zgrep -h 'installd\|softwareupdated' install.log* | sort | less
bzgrep -h '<network name>' wifi.log wifi.log.*.bz2
- syslog -f for
.aslfiles on a Mac. - Plaso:
asl_log(ASL files),text/mac_wifi,text/mac_appfirewall_log,text/syslog:log2timeline.py --parsers 'asl_log,text/mac_wifi,text/syslog' --storage-file logs.plaso ./case/var_log. - mac_apt
ASLplugin readsasl.log,asl.db,*.aslandpowermanagementdata.
Investigator tips
- On any post-Sierra Mac, start with
install.log: it often reaches further back than any other log and records unsigned or third-party packages next to Apple updates. Correlate with install history. install.logrecordsOpened from:with the package path for Installer sessions, which can reveal a download folder or mounted image that no longer exists, andpackage_script_servicelines show what install scripts did.- Read
/etc/asl.conf,/etc/asl/*and/etc/newsyslog.d/*from the evidence, not from your analysis Mac: an attacker or admin can shorten retention or disable a file there. - Rotated archives are compressed (
.gzfor ASL-managed files,.bz2for newsyslogJentries); include them in searches. wifi.logon current releases is a good second source for network location history when the Unified Logs have rotated.- Legacy
sudoand login evidence lives insystem.logonly on 10.11 and earlier images.