SYSLOG SERVER FOR MACOS

Every router log, live on your Mac.

SyslogWatch is a native macOS syslog server. Point any router, NAS, firewall, or Linux box at your Mac and events show up instantly — link flaps, failed logins, firmware warnings, VPN drops, cron failures. Local-first. No cloud account.

RFC 3164 RFC 5424 UDP + TCP Port 1514, no admin Local storage

WORKS OUT OF THE BOX WITH

Ubiquiti / UniFi pfSense OPNsense MikroTik Cisco Synology QNAP Proxmox TrueNAS OpenWrt Linux journald

Real-time clarity

Severity colors and instant filter-as-you-type help you focus on the events that matter. Stop tailing SSH sessions.

Private by design

Logs stay on your Mac. No developer analytics. No advertising network. No cloud account required.

Alerts you control

Keyword rules trigger sound notifications and optional email delivery through your own SMTP server.

No administrator password required

SyslogWatch listens on port 1514 by default, so it starts without any privileged access to your Mac. Configure the same destination port on your router, NAS, or firewall.

PRICING

Free forever. Pro when you're ready.

Free

$0

Enough for a hobby setup or a single-router household.

  • UDP + TCP syslog receiving
  • RFC 3164 + RFC 5424 parsing
  • Live filter as you type
  • Severity color coding
  • Local archive — 7 days
  • Alert rules — up to 3
Download

Pro

$9.99/month

Necessary once you have 3+ devices or care about long-term search.

  • Everything in Free
  • Unlimited local archive
  • Archive full-text search
  • Unlimited alert rules
  • Email notifications via SMTP
  • Multi-host dashboard view
  • CSV / JSON export
  • Priority support
Upgrade in the app

Subscription billed by Apple. Cancel anytime in App Store settings. Free features remain if the subscription lapses.

FAQ

Common questions

Which port does SyslogWatch listen on?

Port 1514 by default (UDP + TCP), so no administrator password is needed. You can change the port in Settings; ports below 1024 require macOS to grant elevated access.

Does it work with UniFi / pfSense / Synology / MikroTik?

Yes. Any device that sends RFC 3164 or RFC 5424 syslog messages works out of the box. Setup guides for the major platforms are on the Support page.

Where are my logs stored?

Only on your Mac, under your user's Application Support directory. Nothing is sent to the developer, to advertising networks, or to any cloud account.

What is the difference between free and Pro?

Free covers live receiving, filtering, 7-day local archive, and up to 3 alert rules. Pro adds unlimited archive with full-text search, unlimited alert rules, email notifications via your own SMTP, multi-host view, and CSV/JSON export.

Do I need a paid subscription to try it?

No. The free tier is fully usable. Pro is only necessary once your log volume or alert-rule count grows beyond the free limits.

How do I cancel Pro?

Open the App Store on your Mac → your profile → Subscriptions → SyslogWatch Pro → Cancel. Your free features continue to work.

Is there a lifetime license?

Not currently. Subscription pricing lets us keep the app maintained across macOS releases. If a lifetime tier becomes available it will be announced here.

What are the system requirements?

macOS 12 Monterey or newer. Apple Silicon or Intel. Approximately 30 MB disk.

CONTACT

Questions or feedback? Email lihulin2002@hotmail.com or open a topic on the Support page.