Mac firewall guides
Send Outbound audit logs to a SIEM
Outbound exports local JSON Lines audit files to a folder your SIEM collector can read. It does not send events directly to a SIEM API.
Updated
Step by step
- Choose a protected export directory. Create a directory appropriate for your collector. Grant the app user write permission and the collector read permission; restrict other access as needed.
- Force AuditExportPath. Use the managed-preferences profile to set AuditExportPath to that directory. Confirm that the setting is forced, not just a user default.
- Generate a controlled event. Make a known connection and apply a rule. Check the local audit log and the exported UTC day file for its verdict and reason.
- Configure the collector. Parse one JSON object per line. Track file offsets across updates and avoid ingesting the same full-day export repeatedly. Apply your own retention policy.
- Test an export failure. Temporarily use an unwritable test destination on a pilot Mac. Confirm that the local log continues and that the app reports the export failure. Restore the correct path.
File naming and retention
Outbound uses YYYY-MM-DD.jsonl filenames based on UTC and keeps 30 days locally. Export copies complete lines at most once a minute. Destination retention belongs to your collector and storage policy.
Illustrative event
The following is a redacted example matching the audit structure, not a captured customer event.
{"timestamp":"2026-10-04T09:00:00Z","flow":{"path":"/usr/bin/curl","remoteHost":"example.com","remotePort":443,"proto":"tcp","direction":"outgoing"},"verdict":"deny","reason":"Illustrative rule decision"}Available fields include process identity, destination, protocol, direction, verdict and reason. Optional fields may be absent; do not turn a missing hostname into an empty or trusted destination.
On-demand export
outboundctl audit export --to /path/to/audit-exportReplace the example path with the directory you prepared. When run as root without a store override, outboundctl uses the console user’s container and refuses to proceed if nobody is signed in.
Use the IT configuration reference and CLI reference as the product sources. JSON Lines is documented at jsonlines.org.
Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.