Skip to content

Apple System Logs (ASL)

Evidence: Apple System Logs (ASL)
Description: Collect Apple System Logs (ASL)
Category: System
Platform: macos
Short Name: asl
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Apple System Logs (ASL) provide historical system and application log entries prior to Unified Logging. This data is essential for legacy system investigations and timeline reconstruction.

This collector gathers structured data about apple system logs (asl).

FieldDescriptionExample
PIDPID123
SenderSenderExample value
FacilityFacilityExample value
MessageMessageExample value
LevelLevelExample value
TimeTime2023-10-15 14:30:25+03:00

This collector copies /private/var/log/asl/*.asl files, converts them via syslog -f -F xml, and records entries into asl.

This evidence is crucial for forensic investigations as it can reveal authentication events, errors, and system activities captured by ASL.