How to Read MacBook Sleep and Wake Logs
Use pmset and macOS unified logs to build a time-bounded timeline, interpret common fields, and avoid overclaiming what a power event proves.
A practical guide to pmset -g log and log show, with time windows, wake reasons, privacy, and limits of attribution.
When a MacBook appears to wake unexpectedly, write down the local time and time zone, whether the display actually turned on, whether the lid was open, whether the Mac was on battery, and what accessories were attached. Also note recent changes: a macOS update, new dock, backup schedule, network setting, or an app that requests background work. A useful review starts with one reproducible event. Searching without a time range can surface unrelated maintenance messages and make ordinary system activity look alarming.
Capture power history
Open Terminal and run pmset -g log | tail -250. The pmset manual describes the command as a way to read and manage power-management settings and logs; output details can vary across macOS releases. Scan the excerpt around the timestamp for a sleep transition, wake transition, reason field, and later return to sleep. Save the unedited excerpt locally before trying configuration changes. The command reports what the system recorded; it does not automatically identify a responsible user-level app. pmset(1)
Query unified logging
Use the macOS log show command to add context, for example log show --last 1h --style compact --predicate 'process == "powerd"'. Adjust the interval to cover the event, using local log show --help for supported date syntax. A powerd filter is a starting point, not a complete trace: kernel or driver messages may use other process names. Some values are redacted, and older records may no longer be retained. Avoid collecting a whole diagnostic archive when a short time window answers the question.
Correlate, then test one variable
Build a timeline from last known sleep to the next visible wake. A reason that mentions network, maintenance, USB, Bluetooth, a timer, or SMC is a clue about the system’s report, not necessarily the original source. A process active after wake may simply be responding. DarkWake denotes a limited power capability state; it does not prove a script ran or that a particular app initiated the event. Apple’s open-source PowerManagement source shows internal state distinctions, but internal code is not a promise that all Macs expose identical events. PowerManagement source
If a dock seems relevant, disconnect only the dock, repeat the same sleep interval, and compare. Keep power source, lid position, network, and workload stable. Then reconnect and repeat if useful. Changing several things at once weakens the evidence. pmset -g assertions is a snapshot of active requests now; it cannot reconstruct every request that existed overnight. Capture it while a suspected task is running and compare before and after the task.
Protect personal information
Logs can expose account names, device names, network addresses, file paths, and usage patterns. Review every excerpt before sharing it. Remove identifiers and include only lines around the event, along with Mac model, macOS version, and relevant conditions. Do not post passwords, full home-directory paths, or a full diagnostic archive to a public forum.
FAQ
Does pmset -g log list every wake? It lists available power-management history, but not every related subsystem message or complete cause chain.
Does DarkWake prove an app was running? No. It cannot establish that a third-party app or lid-angle utility caused the wake. Read DarkWake vs. FullWake.
Why are older entries missing? Unified log retention is finite and varies. Capture evidence soon after reproducing the event.
先看事件,不要只盯着“唤醒”这个词
MacBook 看似意外唤醒时,记下本地时间和时区、显示器是否真的亮起、机盖是否打开、电脑是否使用电池,以及当时连接了哪些配件。还要记录近期变化:macOS 更新、新扩展坞、备份计划、网络设置,或请求后台工作的应用。有效检查从一个可复现事件开始。没有时间范围地搜索会找到不相关的维护消息,让正常系统活动看起来像异常。
收集电源历史
打开终端并运行 pmset -g log | tail -250。pmset 手册将它描述为读取和管理电源管理设置及日志的工具;输出细节会随 macOS 版本变化。根据时间戳查看片段,寻找睡眠转换、唤醒转换、原因字段和随后是否返回睡眠。修改配置前,先在本地保存未编辑的片段。该命令报告系统记录的内容,不会自动识别责任应用。pmset(1)
查询统一日志
使用 macOS 的 log show 命令补充上下文,例如 log show --last 1h --style compact --predicate 'process == "powerd"'。调整时间范围以覆盖事件,并使用本机 log show --help 查看支持的日期语法。powerd 筛选只是起点,不是完整追踪:内核和驱动消息可能使用其他进程名。部分值会被隐去,较旧记录也可能已不再保留。若短时间范围足以回答问题,就不必收集整个诊断包。
先关联记录,再一次测试一个变量
从最近一次已知睡眠到下一次可见唤醒,建立一条时间线。原因字段提到网络、维护、USB、蓝牙、定时器或 SMC,只能说明系统报告的线索,不一定揭示原始来源。唤醒后活动的进程可能只是在响应事件。DarkWake 表示一种受限电源能力状态,不能证明脚本运行了,也不能证明某个应用发起事件。Apple 开源的 PowerManagement 源码展示内部状态区别,但内部代码不保证所有 Mac 都会记录相同事件。PowerManagement 源码
如果怀疑扩展坞,只断开扩展坞,在相同睡眠时长后对比。保持电源来源、机盖位置、网络和任务负载不变。需要时再接回并重复。一次改变多个条件会削弱证据。pmset -g assertions 只显示当前有效请求,不能重建整夜曾存在的所有请求。若要检查某个任务,在它运行时采集,并在任务前后比较。
保护个人信息
日志可能暴露账户名、设备名、网络地址、文件路径和使用习惯。分享前逐行检查,删除标识,只附上事件附近的少量记录,并说明 Mac 型号、macOS 版本和有关条件。不要在公共论坛发布密码、完整用户目录路径或完整诊断包。
常见问题
pmset -g log 会列出每次唤醒吗? 它会列出可用的电源管理历史,但不一定包含所有相关子系统消息或完整原因链。
DarkWake 能证明应用正在运行吗? 不能。它无法证明第三方应用或机盖角度工具造成了唤醒。请读DarkWake 与 FullWake。
旧记录为什么缺失? 统一日志保留时间有限且会变化。复现事件后应尽快收集。
Build a timeline from last known sleep to the next visible wake. A reason that mentions network, maintenance, USB, Bluetooth, a timer, or SMC is a clue about the system’s report, not necessarily the original source. A process active after wake may simply be responding. DarkWake denotes a limited power capability state; it does not prove a script ran or that a particular app initiated the event. Apple’s open-source PowerManagement source shows internal state distinctions, but internal code is not a promise that all Macs expose identical events. PowerManagement source
Make the result reproducible
Keep a small note with the event date, Mac model, macOS version, battery or adapter state, attached devices, and the exact action that preceded the wake. A second occurrence under similar conditions is stronger evidence than a single line. If you are comparing before and after a setting change, use the same observation window and avoid running a different workload. System power behavior changes with OS updates and model capabilities, so include the version instead of assuming another person’s log will look identical. This short record helps Apple Support or a technician ask focused follow-up questions without needing an unfiltered diagnostic archive.
For the paired battery measurement, read closed-lid battery drain.
Sources
Check your Mac before choosing a fix
mac lid close assists sleep and wake using available signals. It does not repair damaged hardware or rewrite Apple part authentication.
Check compatibility →