Skip to main content
Technology add-on for macOS app icon

Technology add-on for macOS

The Technology Add-on for macOS Endpoint Logs (TA-macOS) provides index-time and search-time configurations for collecting and normalizing endpoint logs from macOS systems that have the Splunk Universal Forwarder installed. It focuses on native macOS logs, specifically `/var/log/system.log` and `/var/log/install.log`, and turns them into analytics-ready data for security and operations use cases.Built by Travis Lelle
splunk product badge

Default Version 1.0.0

December 2, 2025

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3

CIM Version: 6.x, 5.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Technology Add-on for macOS Endpoint Logs (TA-macOS) provides index-time and search-time configurations for collecting and normalizing endpoint logs from macOS systems that have the Splunk Universal Forwarder installed. It focuses on native macOS logs, specifically `/var/log/system.log` and `/var/log/install.log`, and turns them into analytics-ready data for security and operations use cases. This add-on defines consistent sourcetypes, handles multiline events correctly, extracts core fields, and provides CIM-friendly eventtypes and tags that support Splunk Enterprise Security data models such as Authentication, Change, and Endpoint.