Nightfall macOS Agent: How to Collect Agent Logs (Local)

Last updated: August 14, 2026

Purpose

To identify where the macOS agent logs are stored to either examine them or provide them to Nightfall Technical Support.

Environment

  • Apple macOS: All Versions

  • Nightfall Agent: All Versions

Resolution

Navigate to the two directories below and copy the files to share with Technical Support:

  • Root Account:

sudo -s
cd /var/root/Library/"Application Support"/NightfallAIAgent/Logs
  • User Account:

cd ~/Library/"Application Support"/NightfallAIAgent/Logs

Note: The log files in both locations will follow the naming convention of:

"ai.nightfall.endpoint year-month-day--time.log"