# Log Storage Location - Elastic Defend Logs macOS

**URL:** https://discuss.elastic.co/t/log-storage-location-elastic-defend-logs-macos/362904
**Category:** Endpoint Security
**Created:** [July 10, 2024, 5:13pm UTC](https://discuss.elastic.co/t/log-storage-location-elastic-defend-logs-macos/362904 "2024-07-10T17:13:38Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)
#### Post date: [July 10, 2024, 6:57pm UTC](https://discuss.elastic.co/t/log-storage-location-elastic-defend-logs-macos/362904/3 "2024-07-10T18:57:58Z")

</div>

Hey @marmai16. Defend buffers events locally to `Endpoint/state/documents`. The files are in an internal/opaque format and not intended to be consumed by anything but Defend. The format may change at any time.

---

_[View the full topic](https://discuss.elastic.co/t/log-storage-location-elastic-defend-logs-macos/362904)._
