Log Storage Location - Elastic Defend Logs macOS

Hello everyone,

i'm currently playing around with the Elastic Defend component. I recently rolled it out to a macOS machine in order to gather process and file events.

My question here is, where are these logs stored locally on the Endpoint ? (This would be at least required if the connection to elastic is lost, so the events have to be buffered temporarily).

I analyzed the log files in /Library/Elastic/ (agent and endpoint) as well as /var/log, but was unable to find these particular events there.

Thank you in advance!

The agent does not buffer on disk yeat, it only has memory buffer.

There is an open issue for adding it: Support the Beats disk queue in Elastic Agent · Issue #3490 · elastic/elastic-agent · GitHub

1 Like

Hey @marmai16. Defend buffers events locally to Endpoint/state/documents. The files are in an internal/opaque format and not intended to be consumed by anything but Defend. The format may change at any time.