Skip to content

Glossary

Unified Logs

Unified Logs are the macOS system logging facility since Sierra, stored in tracev3 files and queried with the log command or a .logarchive.

The Unified Logging system, introduced in macOS Sierra (10.12), replaced most traditional text logs. Entries are written in a compressed binary format to .tracev3 files under /private/var/db/diagnostics, with format strings stored separately in /private/var/db/uuidtext.

Logs are read with the built-in log command (log show, log stats) and can be exported for offline analysis with log collect, which produces a .logarchive bundle. Entries carry a subsystem and category, making predicate filtering effective for logins, sudo, TCC decisions, installs and Gatekeeper activity.

Retention is limited and uneven, and dynamic values are often redacted as <private>. Collect early. See macOS Unified Logs forensics.