What Linux Log Parser reads
A Linux host records authentication, privilege use and service activity in several places at once: text files written by rsyslog (auth.log and syslog on Debian and Ubuntu, secure and messages on RHEL), the binary systemd journal, the audit log written by auditd, and the binary login records wtmp, btmp, utmp and lastlog (or wtmpdb and lastlog2 on newer systems).
This tool reads all of them in your browser and puts them in one timeline. Each line is normalized into an event with its host, program, process id, user, source address and command, and classified: SSH logins and failures, sudo and su, account and password changes, cron and systemd changes, kernel modules, logging being stopped. Logins and logouts are paired into sessions, with the commands run inside them when auditd recorded them.
Where the files are
- /var/log/auth.log, /var/log/syslog (Debian, Ubuntu) and /var/log/secure, /var/log/messages (RHEL, Rocky, Alma, Fedora), with their rotations (.1, .2.gz, dated names).
- /var/log/journal/<machine-id>/*.journal and *.journal~ (persistent journal), /run/log/journal/ (volatile).
- /var/log/audit/audit.log and its rotations (audit.log.1 …).
- /var/log/wtmp, /var/log/btmp, /var/log/lastlog, /run/utmp; wtmpdb at /var/lib/wtmpdb/wtmp.db (Debian 13: /var/log/wtmp.db) and lastlog2 at /var/lib/lastlog/lastlog2.db.
- /etc/localtime or /etc/timezone (time zone for traditional syslog lines) and /etc/passwd (UID to name).
What it shows
- Password guessing followed by a successful login, from the same or another address; logins from addresses an account never used; direct root logins.
- sudo and su use, including interactive root shells, and failed or refused attempts.
- Accounts created, added to admin groups or given a new password; crontab edits, systemd unit files and units that start for the first time; kernel modules.
- Signs of log tampering: gaps in journal sequence numbers, auth lines present in the journal but missing from auth.log, blanked or truncated wtmp records, stopped logging services and log-clearing commands.
- Sessions from login to logout, rebuilt from sshd and PAM lines, systemd-logind, audit session ids and wtmp, with what happened inside them.
What it cannot tell you
- Logs only contain what was logged: without execve audit rules there is no record of commands, and shell builtins are never recorded.
- Messages are written by programs, and any local user can inject look-alike lines with logger. The journal's underscore fields (_UID, _EXE, _CMDLINE) are the trusted ones.
- Traditional syslog lines have no year and no zone: the result depends on the file's date and the zone you set. The tool says when it guessed.
- Findings are leads, not verdicts: administrators produce many of the same traces. Web server logs are not parsed.
How to get the files
- Easiest: as root, tar /var/log, /run/log/journal and /etc/localtime, /etc/timezone, /etc/passwd, /etc/hostname into one .tar.gz and drop it here (see the guide above).
- UAC collections (tar.gz) and Velociraptor ZIPs can be dropped as they are.
- On a dead box, mount the file system read-only and archive the same paths.
Questions
Are my logs uploaded?
No. The files are read and parsed in your browser by WebAssembly running in a Web Worker. Nothing is sent to a server; closing the tab forgets everything.
Can it read binary journal files without journalctl?
Yes. The engine decodes the journal file format directly, including the compact layout of systemd 252 and later and fields compressed with XZ, LZ4 or ZSTD. It also reads journalctl -o export and -o json output.
How does it handle auth.log lines without a year?
Traditional syslog lines (Sep 14 10:02:11) have no year and no time zone. The tool counts years back from the file's modification time (or the newest dated event) and converts local time with the zone from /etc/localtime or /etc/timezone. Both can be set by hand, and every guessed time is marked.
Why do some auth.log lines show as duplicates?
On systemd hosts rsyslog receives its lines from journald, so auth.log and the journal hold the same events. The journal copy has trusted fields and microsecond times, so the text line is marked as a duplicate and hidden by default. Lines present in only one of them are kept and, for auth lines missing from auth.log, reported.
Does it detect deleted log entries?
It reports what can be measured: gaps in journal sequence numbers, auth entries the journal holds but auth.log does not, blanked or truncated wtmp records, and commands that stop logging or delete logs. A clean result does not prove nothing was removed.
Which distributions are supported?
Debian, Ubuntu, RHEL and its rebuilds, Fedora, SUSE and Arch layouts: rsyslog traditional and RFC 3339 formats, RFC 5424, the systemd journal, auditd RAW and ENRICHED logs, wtmp in both the x86_64 and aarch64 record layouts, wtmpdb and lastlog2.