Is it possible to use osquery to collect Mac logs ...
# general
a
Is it possible to use osquery to collect Mac logs and send them to Sumo logic?
j
its... not the best, but possible. Fleet includes the macadmins extension which seems to allow reading logs from the unified log
s
There's a PR up for log access. I expect it to merge in 5.4
🦜 1
The Mac admins extension is a shell exec. May not be great for large data