Tagging back on to <@U0F29L5C4>’s reply above to s...
# macos
c
Tagging back on to @allister’s reply above to see if anyone else has any suggestions on getting opendirectoryd logs into ASL. New to Apple sys admin and Google not terribly helpful. I see opendirectoryd logs in Console under Devices, but I cannot find a specific log file that the daemon is generating to even add to the asl.conf. Looking to capture a log line such as this to then retrieve with osquery via the asl table.
Copy code
Authentication failed for <private> with ODErrorCredentialsInvalid
a
yeah continuing to leverage ASL for that seems like one of those things that COULD be 'deprecated forever but still working' but doable? I'd recommend looking at https://github.com/macadmins/osquery-extension/tree/main/tables/unifiedlog while https://github.com/osquery/osquery/pull/7259 is in flight