osquery-defense-kit/incident_response/unified_log_macos.sql

9 lines
135 B
SQL

-- Retrieves recent entries from the macOS unified log
--
-- tags: postmortem extra
-- platform: darwin
SELECT
*
FROM
unified_log;