Hello everyone... I'm trying to figure out how Apple Remote Desktop logs events... For instance I'd like to see UNIX shell scripts or any shell commands run against my fleet of machines using the ARDAgent ( this would include IP address, action, and username ) similar to Jamf log... Thus far the following command has not been successful at logging on ARD actions... All of my system's have both JAMF and ARD installed for management. Would it be easier to see what's happening on a system digging through Jamf logs for Remote Desktop command and control events or what ?
log stream --predicate 'processImagePath CONTAINS[c] "ARDAgent"'