Skip to content

Posts tagged: #systemd-journal

What to collect for a Linux log investigation and how: one tar command on a live host, journalctl export, ausearch, UAC, Velociraptor, or a mounted disk image.
How to prove Linux logs were edited or deleted: journal seqnum gaps, lines missing from auth.log, blanked wtmp records, stopped daemons and clearing commands.
How the four Linux log families fit together in an investigation, what each one proves, where they disagree, and how to merge them into one timeline.
systemd journal forensics without journalctl: the file format, trusted fields, compression, sequence-number gaps, dirty .journal~ files and time fields.