Description

The majority of MacOS log-data is stored as a sequence of unified logs.

On a live Mac, the log command can be used to extract these logs into a *.logarchive folder that can be read by another Mac using the Console application or the log command.

The script’s purpose is to mimic this behaviour by extracting the contents of the following folders into a single output folder with a *.logarchive file-extension:

  • /private/var/db/diagnostic
  • /private/var/db/uuidtext

In order for the output folder to be treated as a log-archive by the latest versions of MacOS, the script must also create an XML property-list file called Info.plist containing a single integer value called OSArchiveVersion.

At the time of writing, the latest version of MacOS Sequoia sets this value to 5, so this is the default value used by the script. The user can, however, set another value.

Before running the script, the user must highlight the relevant db folder in EnCase’s tree-pane or table-pane.

If the aforementioned folders are in a folder with a different name - perhaps because they’ve been acquired logically - the user must highlight the diagnostic or uuidtext folder in the table-pane.

Progress can be monitored via the console.

This script was developed for use in EnCase training. For more details, please click the following link:

Releases

Release
Size
Date
MacOS Unified Log Extractor 1.0
122.3 KB
  |  
Apr 23, 2025
More info Less info
Product compatibility
Version 1.0.0
Release notes

First release.

Developed using EnCase 25.1.0.64.

Languages
English

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service.
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2025-4-2-6380 | Tue Apr 15 15:26:15 PDT 2025