Where Is the macOS Firewall Log?
macOS firewall events went to appfirewall.log, now to unified logs. Both routes plus the socketfilterfw tool.
Last updated
The classic macOS firewall log is /var/log/appfirewall.log, a plain-text file readable in Console or tail. That file belongs to older releases and may simply not exist on current systems, which surprises people following old guides.
Recent macOS versions moved firewall events into unified logging. Query the trace store for the socketfilterfw process instead of hunting the flat file. The daemon binary behind both eras lives at /usr/libexec/ApplicationFirewall/socketfilterfw. Note the firewall filters inbound per app only; packet detail needs pf or tcpdump instead.
Where macOS Firewall stores this, by platform
/var/log/appfirewall.log
Legacy plain-text log; absent on recent releases including Tahoe. Modern route: log show --predicate 'process == "socketfilterfw"' against /var/db/diagnostics. Daemon at /usr/libexec/ApplicationFirewall/socketfilterfw. Older toggles like --setloggingmode are gone from current man pages.
Frequently asked questions
Why is there no appfirewall.log on my Mac?
Apple moved firewall events into unified logging, so the flat file stopped appearing on recent releases. Query the log store for the socketfilterfw process instead. Console shows the same events under the unified view.
How do I watch firewall events live?
Stream the unified log filtered to socketfilterfw, or tail the legacy file where it still exists. Live packet detail is out of scope here: the app firewall logs allow and deny decisions, and tcpdump covers the wire.
Does the firewall log outbound connections?
No. The built-in firewall governs inbound per-application access only. Outbound per-process control needs third-party tools. Check pf logs and packet captures when the question is what left the machine.
Notice an outdated path? Let us know.