• a

    Aakif Siddiqui

    2 months ago
    Is it possible to use osquery to collect Mac logs and send them to Sumo logic?
  • j

    Jason

    2 months ago
    its... not the best, but possible. Fleet includes the macadmins extension which seems to allow reading logs from the unified log
  • s

    seph

    2 months ago
    There's a PR up for log access. I expect it to merge in 5.4
  • The Mac admins extension is a shell exec. May not be great for large data