poisontap
poisontap copied to clipboard
Where network changes are logged in macOS X?
In Console.app I see that "configd" process send log messages like "network changed: v4(en0:1.0.0.11) DNS Proxy SMB" But there is no way to parse that logs because they are not saved on any file.
Anyone knows how to match this with Logstash or OSSEC for example?