Compose & send
RFC 3164 and RFC 5424 formatting, templates, structured data, message padding, pacing, retries, run cancellation and dry-run previews.
Native macOS · SwiftUI · Development preview
LogSalvo is becoming a native Mac workspace for generating, receiving, inspecting and forwarding syslog traffic—built for engineers who need to see exactly what crossed the wire.
A new identity
The Swift edition retires the legacy Tech Shed application artwork in favour of the LogSalvo Traffic Pulse: a dedicated product mark inspired by messages moving through a live network.
The cyan pulse, deep navy interface and “Syslog Traffic Studio” descriptor now run through the app and its macOS icon, giving LogSalvo an identity of its own while keeping its Tech Shed roots.
The workspace
Two focused workspaces cover both sides of a syslog conversation without hiding the protocol details.
Capabilities
RFC 3164 and RFC 5424 formatting, templates, structured data, message padding, pacing, retries, run cancellation and dry-run previews.
UDP, TCP and TLS with system or custom CA trust, Keychain-backed client identities, IPv4 and IPv6 resolution and explicit source binding.
Understand RFC syslog alongside JSON, Cisco IOS, CEF and UniFi payloads, with PRI decoding, search, sorting and a raw-message inspector.
Relay exact payloads to multiple UDP, TCP or TLS destinations with filters, bounded queues, retries, loop prevention and health counters.
Pause and queue a live view, bound in-memory retention and export selected traffic as CSV, JSON Lines or unchanged raw payloads.
Opt-in macOS notifications support privacy-conscious summaries, rules, deduplication, rate limiting and click-through to the matching event.
Native by design
The Swift migration separates protocol handling, transport, receiving and privileged operations into focused modules. The interface is built in SwiftUI, supports system, light and dark appearances, and uses accessibility-aware native controls.
Listening on ports 1–1023 uses an authenticated LaunchDaemon helper with a narrow XPC boundary. The main LogSalvo interface continues to run as the signed-in user.
Project status
Version 0.4.0 is a development release for Apple silicon, with the core sender, receiver, forwarding, notification and settings workflows in place. Production signing, notarisation and final interface parity are still on the roadmap.
The original Python edition remains the cross-platform reference while the native macOS app develops alongside it.
Read about the original LogSalvo →