Glossary
Plain-language definitions of the Linux logging terms used across the blog and the tool.
- auid (audit login UID)
- The audit login UID: the UID a user logged in with, set once at login and kept by every child process, including through sudo and su.
- auditd
- The Linux audit daemon, which writes kernel audit records (logins, sessions, executed programs, watched files) to /var/log/audit/audit.log.
- EXECVE record
- The audit.log record that holds the arguments of an executed program, argc and a0..aN, with hex encoding for arguments containing spaces or special characters.
- Journal sequence number (seqnum)
- The counter journald assigns to every journal entry, shared by all journal files of a machine; missing numbers reveal entries that no longer exist.
- lastlog
- The file /var/log/lastlog: one fixed-size slot per UID holding that account's most recent login time, terminal and remote host.
- pam_unix
- The standard PAM module for password authentication and session accounting, which writes the pam_unix(service:type) lines in auth.log and secure.
- RFC 3164 (traditional syslog format)
- The traditional BSD syslog line format, Mmm dd HH:MM:SS host tag: message, in local time with no year and no time zone.
- RFC 5424 (syslog protocol)
- The current syslog protocol format, with a version number, a full timestamp with time zone, and structured data, used mainly by forwarders and collectors.
- rsyslog
- The syslog daemon on most Linux distributions, which writes text logs such as auth.log, syslog, secure and messages, usually fed by journald.
- systemd journal
- The binary log of systemd-journald: structured FIELD=value entries with trusted sender fields and microsecond UTC timestamps, often the only system log.
- systemd-logind
- The systemd login manager, which numbers user sessions and logs New session N of user X and Removed session N.
- UAC (Unix-like Artifacts Collector)
- An open-source shell-script collector for Linux and other Unix systems that gathers logs and artifacts into a tar.gz for forensic analysis.
- utmp
- The file /run/utmp listing the sessions open right now, in the same struct utmp format as wtmp; cleared at every boot.
- wtmp and btmp
- Binary Linux login records: /var/log/wtmp holds the history of sessions, boots and shutdowns; /var/log/btmp holds failed login attempts.
- wtmpdb
- The SQLite replacement for wtmp (wtmp.db), with one row per session, times in microseconds and the PAM service name; used by openSUSE and Debian 13.