SOLVED

Mac OS Logs

%3CLINGO-SUB%20id%3D%22lingo-sub-1469285%22%20slang%3D%22en-US%22%3EMac%20OS%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1469285%22%20slang%3D%22en-US%22%3E%3CP%3EWith%20no%20Agent%20readily%20available%20for%20Mac%20OS%20devices%20has%20anyone%20been%20able%20to%20onboard%20any%20logs%20into%20Azure%20Sentinel%20by%20Syslog%20or%20any%20other%20method%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1469285%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20Sentinel%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Elogs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMac%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Emac%20os%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1470276%22%20slang%3D%22en-US%22%3ERe%3A%20Mac%20OS%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1470276%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F553664%22%20target%3D%22_blank%22%3E%40arran1580%3C%2FA%3E%26nbsp%3BIf%20you're%20using%20Intune%20(Endpoint%20Manager)%20to%20manage%20the%20Mac%20devices%2C%20you%20can%20do%20the%20following%20and%20then%20setup%20custom%20log%20ingestion%20into%20the%20Log%20Analytics%20workspace%20for%20Sentinel.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fapps%2Fmacos-shell-scripts%23collect-device-logs%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fapps%2Fmacos-shell-scripts%23collect-device-logs%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20will%20still%20need%20to%20do%20some%20post-ingestion%20parsing%2C%20though.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1477307%22%20slang%3D%22en-US%22%3ERe%3A%20Mac%20OS%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1477307%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F324945%22%20target%3D%22_blank%22%3E%40rodtrent%3C%2FA%3E%26nbsp%3Bthanks%20for%20providing%20this%20information.%20I%20will%20look%20further%20at%20Intune%20(Endpoint%20Manager)%20integration%20with%20Azure%20Sentinel.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1480203%22%20slang%3D%22en-US%22%3ERe%3A%20Mac%20OS%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1480203%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F553664%22%20target%3D%22_blank%22%3E%40arran1580%3C%2FA%3E%26nbsp%3B%3A%20MacOS%20natively%20supports%20syslog.%20You%20can%20find%20instructions%20on%20how%20to%20forward%20it%20%3CA%20href%3D%22https%3A%2F%2Fwiki.splunk.com%2FCommunity%3AHowTo_Configure_Mac_OS_X_Syslog_To_Forward_Data%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1480319%22%20slang%3D%22en-US%22%3ERe%3A%20Mac%20OS%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1480319%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F293879%22%20target%3D%22_blank%22%3E%40Ofer_Shezaf%3C%2FA%3Ethanks%20for%20providing%20the%20information%20around%20syslog%20for%20Mac.%3C%2FP%3E%3CP%3ESyslog%20was%20originally%20how%20I%20was%20planning%20to%20get%20the%20logs%20integrated%20with%20Azure%20Sentinel%20however%2C%20I've%20read%20many%20forms%20and%20websites%20stating%20that%26nbsp%3Bfunctionality%20of%20syslog%20for%20multiple%20OS%20is%20broken%20due%20to%20System%20Integrity%20Protection%20(SIP)%20in%20Mac%20OS%20X%2010.11%20onwards.%20Some%20know%20examples%20of%20Mac%20OS%20X%20which%20are%20reported%20to%20have%20a%20lot%20of%20issues%20with%20Syslog%20include%20Sierra%20and%20High%20Sierra.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1632178%22%20slang%3D%22en-US%22%3ERe%3A%20Mac%20OS%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1632178%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F553664%22%20target%3D%22_blank%22%3E%40arran1580%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EYou%20could%20look%20at%20CMDReporter.%20When%20testing%20out%20multiple%20SIEMS%20our%20MAC%20systems%20became%20a%20big%20sticking%20point%20based%20on%20how%20it%20now%20consolidates%20its%20logs%20into%20the%20Unified%20Logging%20system.%20CMDReporter%20was%20a%20cheap%20third%20party%20tool%20that%20would%20parse%20the%20data%20out%20of%20the%20unified%20logging%20system%20and%20dump%20it%20to%20a%20JSON%20file%20to%20send%20to%20the%20respective%20Log%20Correlation%20system%20of%20your%20choosing.%20Seemed%20to%20be%20the%20best%20way%20forward%20for%20us.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

With no Agent readily available for Mac OS devices has anyone been able to onboard any logs into Azure Sentinel by Syslog or any other method?

5 Replies
Best Response confirmed by arran1580 (Occasional Contributor)
Solution

@arran1580 If you're using Intune (Endpoint Manager) to manage the Mac devices, you can do the following and then setup custom log ingestion into the Log Analytics workspace for Sentinel.

 

https://docs.microsoft.com/en-us/mem/intune/apps/macos-shell-scripts#collect-device-logs

 

You will still need to do some post-ingestion parsing, though.

@rodtrent thanks for providing this information. I will look further at Intune (Endpoint Manager) integration with Azure Sentinel.

@arran1580 : MacOS natively supports syslog. You can find instructions on how to forward it here.

@Ofer_Shezafthanks for providing the information around syslog for Mac.

Syslog was originally how I was planning to get the logs integrated with Azure Sentinel however, I've read many forms and websites stating that functionality of syslog for multiple OS is broken due to System Integrity Protection (SIP) in Mac OS X 10.11 onwards. Some know examples of Mac OS X which are reported to have a lot of issues with Syslog include Sierra and High Sierra.

@arran1580 
You could look at CMDReporter. When testing out multiple SIEMS our MAC systems became a big sticking point based on how it now consolidates its logs into the Unified Logging system. CMDReporter was a cheap third party tool that would parse the data out of the unified logging system and dump it to a JSON file to send to the respective Log Correlation system of your choosing. Seemed to be the best way forward for us.