# logd

Canonical page: https://vitalsmac.com/glossary/logd

Activity Monitor glossary, Processes you will see. What is logd on Mac?

Also: unified logging

**Short answer:** logd is the macOS process that runs the unified log, the system-wide record of what macOS and your apps report while they run. Every process hands its log messages to logd, which compresses them, keeps recent ones in memory and saves the rest to a log store on disk, where the Console app and the log command in Terminal read them.

There is one logd, it runs as root, and launchd starts it when the Mac starts up. Since macOS Sierra, most messages no longer go to text files in /var/log. Apps hand them to logd, which stores them in a compressed binary format in /var/db/diagnostics, with the fixed text of each message kept in /var/db/uuidtext. That is why you read the log with Console or the log command rather than by opening a file.

Its CPU and disk use follow how much the rest of the Mac is logging. On a quiet Mac it uses a fraction of a percent. When logd is near the top of the list, it is almost never logd's own fault: another process is writing messages much faster than usual, and logd is doing the work of storing them.

## Why logd is using so much CPU or disk

An app or background process is logging in a loop. A process that fails and retries many times a second, such as a network client that cannot reach its server, a stuck sync, or a driver that reports the same error over and over, can write hundreds of thousands of messages a minute. logd compresses and saves every one, and its CPU and Bytes Written rise with them.

Extra logging turned on for troubleshooting has the same effect. A logging profile installed for a bug report, or a change made with the `log config` command, makes logd save messages it would normally keep only in memory.

## What to do about it

Find the process that is flooding the log and deal with that process, not with logd. In Terminal, `log stats --last 5m` ranks processes by how much they logged in the last five minutes. Quit or update the app at the top, or restart the Mac if it is a background process that is stuck.

If you installed a logging profile that you no longer need, remove it in System Settings → General → Device Management. Quitting logd does not help: macOS starts it again at once, and the process that is flooding the log carries on.

## How to find the process flooding the log

logd is the one doing the storing, so the useful question is who is doing the writing. Activity Monitor shows the cost and Terminal shows the culprit.

1. Open Activity Monitor, click the CPU tab, choose View → All Processes, and type `logd` in the search field. Note its % CPU.
2. Click the Disk tab and watch logd's Bytes Written. A figure that climbs quickly means it is saving a flood of messages to disk.
3. Clear the search field and sort the CPU tab by % CPU. The process that is flooding the log is often busy itself, and may be restarting over and over with a new PID each time.
4. Open Terminal and run `log stats --last 5m`. Under processes it lists the processes that logged the most in the last five minutes, with their number of events and bytes. WindowServer and a few other system processes log a lot on every Mac, so look for a process with an unusual share, or one that should be idle.
5. To read what that process is saying, run `log show --last 5m --predicate 'process == "Name"'`, with the process name in place of Name. To watch it live, use `log stream` with the same predicate, and press Control-C to stop.

## Normal logd use vs a problem

Normal: logd stays well under a few percent of CPU, with short rises when the Mac starts up, wakes from sleep or when many apps open at once.

Worth looking into: logd stays near the top of the CPU list for minutes at a time, or its Bytes Written keeps growing fast while you are doing little. These are the usual causes:

- A process that fails and retries in a tight loop, such as a network client that cannot reach its server or a sync that is stuck.
- A helper that crashes and is started again straight away, logging the same startup and failure each time.
- Debug or info logging turned on with `log config`, or by a logging profile installed for a bug report.
- An app with verbose logging switched on in its own settings, or a test build of an app that logs everything.
- Console left streaming, or a tool that reads the live log all the time. That cost shows up mostly in diagnosticd, logd's companion.

## Reading the log in Console

Console, in Applications → Utilities, shows the same log in a window. Click Start in the toolbar to see messages as they arrive, and type a process name in the search field to show only the messages that mention it. When one process fills the screen faster than you can read, you have found what logd is busy with.

Stop streaming when you are done. While Console shows the live log, diagnosticd and the processes that log do extra work, which is the opposite of what you want on a Mac that is already busy.

## Questions people ask

### What is logd on Mac?

The macOS process behind the unified log. Every app and system process sends its log messages to logd, which compresses and stores them so Console and the log command can show them.

### Why is logd using high CPU?

Almost always because another process is writing log messages in a loop, and logd has to store them all. Run `log stats --last 5m` in Terminal to see which process is logging the most.

### Can I delete the logs logd keeps?

You can, but there is rarely a reason to. macOS purges old messages on its own when the log store reaches its size limit, so it does not grow without end. If you need to clear it, `sudo log erase --all` removes the stored messages, along with the history you or Apple Support would need to diagnose a problem. Do not delete /var/db/diagnostics or /var/db/uuidtext by hand.

### What is diagnosticd on Mac?

Another part of the unified logging system. logd stores messages, and diagnosticd delivers them live to Console and to `log stream`. It uses more CPU only while one of those is showing the live log.

### Is it safe to quit logd?

It does no lasting harm, because macOS starts it again at once, but it does no good either. The process that was flooding the log carries on, and logd picks up the work again as soon as it restarts.

## In Vitals

logd runs as root, so Vitals measures it when its optional helper is on. Without the helper it is counted among the processes the window says it cannot measure.

## Related

- [launchd](https://vitalsmac.com/glossary/launchd)
- [System Data](https://vitalsmac.com/glossary/system-data)
- [% CPU](https://vitalsmac.com/glossary/cpu-percent)
- [Unmeasured processes](https://vitalsmac.com/glossary/unmeasured-processes)

Looking for something better than Activity Monitor? See [the best Activity Monitor alternatives for Mac](https://vitalsmac.com/best-activity-monitor-alternatives), or [every term in the glossary](https://vitalsmac.com/glossary).
