macOS

Where Does macOS Save sysdiagnose Output?

sysdiagnose bundles land in /var/tmp as dated tar.gz archives. Trigger keys, output pattern and contents.

Last updated

sysdiagnose collects a full diagnostic bundle: spindumps, process samples, filesystem usage traces, logs, crash reports and a System Profiler snapshot. The run takes several minutes and needs an admin password with a confirmation keypress.

Output lands in /var/tmp as a dated tar.gz archive, and Finder opens the result on completion. A flag redirects elsewhere, and a help flag prints the default directory. The Finder key chord and the Activity Monitor diagnostics item trigger the same collection without Terminal.

Where macOS sysdiagnose stores this, by platform

macOS
/var/tmp/sysdiagnose_*.tar.gz

Dated pattern like sysdiagnose_YYYY.MM.DD_HH-MM-SS-0700_*.tar.gz. Trigger with sudo sysdiagnose, the Control Option Command Shift Period chord from Finder, or Activity Monitor diagnostics. Redirect with sudo sysdiagnose -f <dir>; print the default with sysdiagnose -H.

Frequently asked questions

How do I run sysdiagnose on a Mac?

Open Terminal and run sudo sysdiagnose, press Enter at the confirmation, and wait several minutes for collection. Finder reveals the tar.gz in /var/tmp when done. The key chord from Finder starts the same run without typing.

What is inside a sysdiagnose bundle?

Spindumps, top and fs_usage samples, system and app logs, crash reports and full System Profiler output. Support teams ask for it because one archive covers hangs, leaks and kernel events together. It can be large, so compress before uploading.

Can I save sysdiagnose somewhere else?

Yes with sudo sysdiagnose -f followed by the target directory, such as the Desktop for easy upload. The default stays /var/tmp otherwise. Old bundles do not auto-delete, so remove sent ones to reclaim space.

Notice an outdated path? Let us know.