LogRaker Features Pricing Docs Release Notes Blog Download

← Documentation

Unified Log streams (this Mac)

On a Local System Source, a Stream can follow this Mac's unified log - the messages the Console app shows - instead of tailing a file. Watch a system service, another app, or iCloud sync activity live, next to your other Streams.

Unified Log streams are available in the Web Edition. The App Store Edition can't read the system log: a Unified Log stream that reaches it through iCloud sync shows a message instead of running.

Creating a Unified Log stream

+ ▸ 'New Stream…' under a Local System Source, then set Source to Unified Log. The Path row is replaced by:

  • Subsystems - the subsystems to follow, one per pill, for example com.apple.cloudkit. Return, a comma or a space after a name makes it a pill.
  • Presets - adds the subsystems for a common task: 'Bluetooth', 'CloudKit' (iCloud sync, com.apple.cloudkit and com.apple.coredata), 'DNS', 'iCloud Drive', 'Networking', 'Power & Sleep', 'Privacy Permissions', 'Push Notifications', 'Time Machine', or 'Wi-Fi'.
  • Processes - the processes to follow, one per pill, for example cloudd. Return or a comma after a name makes it a pill; a name can contain spaces. Click 'Choose…' to pick from the processes that wrote to the log in the last 5 minutes, narrowed to the subsystems you've set. Click a checked process to remove it again.
  • Level - the lowest level to include. Choosing a level shows that level and everything more severe: Default (the default) also shows Error and Fault, Error also shows Fault. Info and Debug add those messages, which some processes write many times a second.
  • Preview - the filter the Stream will run, updated as you change the controls.

Names must match exactly. Fill in at least one subsystem or process. With both filled in, a message must match one of the subsystems and one of the processes.

The Filter pills, Strip matched text, and Auto-stream at startup options work exactly as they do for file Streams - the Filter is applied on screen, on top of what the log returns.

To find a subsystem or process name, look the message up in Console (Applications ▸ Utilities).

What you see

  • Severity - Fault shows as Critical, Error as Error, Default as Notice, Info as Info, and Debug as Debug.
  • Process - the process that wrote the message.
  • Message - the text, led by its subsystem and category in brackets, for example [com.apple.cloudkit:OP]. A message spanning several lines shows on one row, each line break written as \n.

Values macOS marks as private show as <private>, as they do in Console. See Seeing private values.

Seeing private values

macOS hides private values when a message is written, so neither LogRaker nor Console can show them later. To have a subsystem write its values in the clear, turn on private data for it in Terminal. You need an administrator password:

sudo defaults write /Library/Preferences/Logging/Subsystems/com.apple.cloudkit DEFAULT-OPTIONS -dict Enable-Private-Data -bool true

Replace com.apple.cloudkit with the subsystem you follow, and run it once per subsystem; the 'CloudKit' preset also uses com.apple.coredata. Messages written after that show their values. Messages already written stay <private>.

Some values are marked sensitive rather than private and show as <mask.hash: …>. This setting doesn't reveal them.

Private values can include personal information, and while the setting is on, any app that can read the log sees them. Turn it off when you're done:

sudo rm /Library/Preferences/Logging/Subsystems/com.apple.cloudkit.plist

To turn it on for every subsystem at once, administrators can install a configuration profile with the com.apple.system.logging payload and Enable-Private-Data set to true.

History

On connect, LogRaker shows the number of lines set in Settings ▸ Streams ▸ Initial history, taken from the last hour of the log. Reconnects show only new lines.

Errors

A Stream with no subsystem and no process stops with “Add at least one subsystem or process”. If the log doesn't answer, the Stream reports “Couldn't open this Mac's unified log” and retries, as any Stream does after a lost connection. If this version of macOS can't provide the live feed at all, the Stream stops with the same message.

Use in Monitors and Layouts

A Unified Log stream is an ordinary Stream - it can be added to a Layout pane and watched by a Monitor just like a file Stream.

© 2026 Thomas Gumz · Native macOS log monitoring Features Pricing Download Docs Blog Changelog About Privacy

Also by Thomas Gumz: PanoPaper, your security cameras as live video wallpaper.

Amazon Web Services, AWS, Amazon CloudWatch, and Amazon S3 are trademarks of Amazon.com, Inc. or its affiliates. Google Cloud and Firebase are trademarks of Google LLC. Supabase is a trademark of Supabase, Inc. LogRaker is an independent product and is not affiliated with, endorsed by, or sponsored by Amazon, Google, or Supabase.