The Apple Unified Log (AUL) is the central logging system on iOS, iPadOS, macOS and watchOS. Apple introduced it in 2016 with iOS 10 and macOS 10.12 Sierra, where it replaced the old syslog and ASL files. The operating system, Apple’s own apps and third-party apps all write to the same log. For a forensic examiner that makes it one of the densest records of user activity on an Apple device, with timestamps down to the microsecond. It is also one of the first to disappear.
What the log records
Apple built the Unified Log for developers and its own engineers, not for investigators. Even so, it captures a great deal of what a user does:
- Unlocking a Mac with Touch ID
- Touches on the screen and on the keyboard
- Switching on airplane mode
- Connecting to CarPlay
- Triggering Emergency SOS
- In some cases, the phone number that was dialed
Much of this exists nowhere else on the device.
Because the log is a diagnostic tool, Apple changes what it writes between OS versions without announcing it. An artifact I document on iOS 26 may look different on iOS 18, or not exist at all. Every artifact belongs to a specific OS version and has to be validated on a reference device before it goes into a report.
Anatomy of a log entry
Here is a single entry, recorded when a key was pressed in Apple Mail:
2025-10-03 11:28:20.901236+0200 localhost MobileMail[679]: (UIKitCore) [com.apple.UIKit:KeyboardTouch] touch down
Reading from left to right, the entry contains:
- The timestamp with microseconds and the UTC offset.
- The process and its process ID (
MobileMail, 679). - The library that wrote the entry (
UIKitCore). - The subsystem and category (
com.apple.UIKit,KeyboardTouch). - The message itself.
Each entry also has a level: default, info, debug, error or fault. When you export to JSON you get more fields, such as the boot UUID. The boot UUID tells you which boot session the entry belongs to.
Where the log is stored
On disk, the log lives in two places:
/private/var/db/diagnosticsholds the compressed.tracev3files./private/var/db/uuidtextholds the format strings that turn those entries back into readable messages.
You need both. Without uuidtext, most messages cannot be reconstructed. Put both folders together in a directory ending in .logarchive, and Apple’s log tool can read it. On an iPhone these folders are only reachable through a full file system extraction. In practice you usually get the log through log collect or a sysdiagnose, both covered in the investigation guide.
How long the log lasts
The log rolls over based on size, not on a fixed number of days. A busy device overwrites its history faster than a quiet one. The acquisition method also matters, as I measured in Thesis Friday #7:
| Platform | log collect | sysdiagnose |
|---|---|---|
| iPhone | 14 days | 2 days |
| Mac | 30 days | 2 days |
The age of the oldest entry does not tell you whether a given moment is still covered. On a busy iPhone, the kernel lines of an unlock were gone within 13 hours while the archive still reached back weeks (Thesis Friday #28).
If a case depends on the Unified Log, the log has to be secured in the first days, not after the device has spent two weeks in an evidence locker.
What the log does not tell you
Three limits matter most:
- Redaction. Many values are replaced by
<private>. User names, match results and many strings are hidden unless logging profiles were active on the device. - Hidden levels.
log showhides info and debug entries unless you add--info --debug. - No intent. The log records system state, not what a person meant to do. A line saying the keybag changed from locked to unlocked tells you the device was unlocked. It does not tell you who was holding it.
That is why I never report a single log line as an event. One line is a data point. What happened only becomes visible in the sequence of entries around it, as I explain in Why a single artifact never tells the whole story.
Frequently asked questions
How long does iOS keep Unified Log data?
There is no fixed period. The log rolls over by volume, so a busy phone loses history faster than an idle one. In my tests the kernel lines of an unlock were gone within 13 hours on a phone in daily use and still complete after 88 hours on an idle one (#28).
Is the Unified Log part of a standard iPhone extraction?
Not in a regular logical backup. You collect it separately with log collect or a sysdiagnose, or rebuild it from a full file system extraction.
Can I read the Unified Log on Windows?
Apple’s log tool only runs on macOS. A common workflow is to convert the logarchive to JSON once on a Mac and analyse it anywhere after that. Open-source parsers such as Mandiant’s macos-UnifiedLogs can also read the raw .tracev3 files on other platforms.
What is the difference between the Unified Log and a sysdiagnose?
A sysdiagnose is a diagnostic bundle. One of the things inside it is a logarchive, but with a much shorter time window than a direct log collect.
Does the Unified Log contain message content or photos?
No. It records system events, not user content. Some events do carry revealing details, such as a dialed number.
About the author
Tim Korver has worked in digital forensics and incident response in law enforcement for more than 14 years. He developed the Anchored Log Reconstruction (ALR) method for interpreting the Unified Log as evidence. All log data on this site comes from his own reference devices.
Ready to work with it? Read how to investigate the Apple Unified Log.
