Document toolboxDocument toolbox

box.macos

Introduction

The tags beginning with box.macos identify events generated by macOS.

Valid tags and data tables

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

macOS

box.macos

box.macos

box.macos.host[abcd].ip[0.0.0.0]

How is the data sent to Devo?

You can forward logs generated by macOS X using any Syslog drain (for example, Syslog-ng).

Table structure

These are the fields displayed in this table:

box.macos

Field

Type

Source field name

Extra fields

Field

Type

Source field name

Extra fields

eventdate

timestamp

 

 

hostName

str

 

 

facility

str

 

 

level

str

vlevel

 

eventGenerationDate

str

 

 

srcHostName

str

 

 

processName

str

 

 

processId

str

 

 

managedProcess

str

 

 

msgId

str

 

 

structuredData

str

 

 

message

str

 

 

rawMessage

str

 

✓

hostchain

str

 

✓

tag

str

 

✓