Firewall logs

Discussion in 'macOS Sierra (10.12)' started by fivenotrump, Nov 3, 2016.

  1. fivenotrump macrumors 6502

    Joined:
    Apr 15, 2009
    Location:
    Central England
    #1
    Has anyone discovered whether the built-in firewall still logs? If so, please share how to read them!
     
  2. Floris macrumors 68020

    Floris

    Joined:
    Sep 7, 2007
    Location:
    Netherlands
    #2
  3. fivenotrump thread starter macrumors 6502

    Joined:
    Apr 15, 2009
    Location:
    Central England
    #3
    There is no such tab or menu item in Console.app. There is an empty /var/log/appfirewall.log – this is where firewall events were logged pre-Sierra.
     
  4. KALLT macrumors 601

    Joined:
    Sep 23, 2008
  5. fivenotrump thread starter macrumors 6502

    Joined:
    Apr 15, 2009
    Location:
    Central England
  6. KALLT macrumors 601

    Joined:
    Sep 23, 2008
  7. fivenotrump thread starter macrumors 6502

    Joined:
    Apr 15, 2009
    Location:
    Central England
    #7
    check logging is on (should be):
    /usr/libexec/ApplicationFirewall/socketfilterfw --getloggingmode
    check logging option:
    /usr/libexec/ApplicationFirewall/socketfilterfw --getloggingopt
    mine said 'throttled', so:
    sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setloggingopt detail

    check logging config for subsystem:
    sudo log config --status --subsystem com.apple.alf
    likely says "Mode for 'com.apple.alf' INFO PERSIST_DEFAULT" so:
    sudo log config --mode "persist:info" --subsystem com.apple.alf

    now use log(1) like
    log show --predicate 'subsystem == "com.apple.alf"' --info --last 1h

    I do get some log entries when expected but they all have the same useful message "<private>"
     
  8. Hack5190 macrumors 6502a

    Hack5190

    Joined:
    Oct 21, 2015
    Location:
    Stuck on Earth in the USA
    #8
    Has there been any further updates / progress on how to enable firewall logging in Sierra?
     
  9. fivenotrump thread starter macrumors 6502

    Joined:
    Apr 15, 2009
    Location:
    Central England
    #9
    No change with 10.12.3. I have an open radar.
     
  10. Hack5190, Mar 2, 2017
    Last edited: Mar 2, 2017

    Hack5190 macrumors 6502a

    Hack5190

    Joined:
    Oct 21, 2015
    Location:
    Stuck on Earth in the USA
    #10
    I wasn't aware of "open radar" before, thanks for the information!

    Care to share the link for your radar ?
     
  11. fivenotrump thread starter macrumors 6502

    Joined:
    Apr 15, 2009
    Location:
    Central England
    #11
    Sorry for the ambiguity: I have a radar open with Apple, not entered in to OpenRadar. It would be helpful if others with similar problems were to open radars with Apple as this lends weight when they are considering priorities.
     

Share This Page