Skip to content

Glossary

Plain-language definitions of the Linux logging terms used across the blog and the tool.

auid (audit login UID)
The audit login UID: the UID a user logged in with, set once at login and kept by every child process, including through sudo and su.
auditd
The Linux audit daemon, which writes kernel audit records (logins, sessions, executed programs, watched files) to /var/log/audit/audit.log.
EXECVE record
The audit.log record that holds the arguments of an executed program, argc and a0..aN, with hex encoding for arguments containing spaces or special characters.
Journal sequence number (seqnum)
The counter journald assigns to every journal entry, shared by all journal files of a machine; missing numbers reveal entries that no longer exist.
lastlog
The file /var/log/lastlog: one fixed-size slot per UID holding that account's most recent login time, terminal and remote host.
pam_unix
The standard PAM module for password authentication and session accounting, which writes the pam_unix(service:type) lines in auth.log and secure.
RFC 3164 (traditional syslog format)
The traditional BSD syslog line format, Mmm dd HH:MM:SS host tag: message, in local time with no year and no time zone.
RFC 5424 (syslog protocol)
The current syslog protocol format, with a version number, a full timestamp with time zone, and structured data, used mainly by forwarders and collectors.
rsyslog
The syslog daemon on most Linux distributions, which writes text logs such as auth.log, syslog, secure and messages, usually fed by journald.
systemd journal
The binary log of systemd-journald: structured FIELD=value entries with trusted sender fields and microsecond UTC timestamps, often the only system log.
systemd-logind
The systemd login manager, which numbers user sessions and logs New session N of user X and Removed session N.
UAC (Unix-like Artifacts Collector)
An open-source shell-script collector for Linux and other Unix systems that gathers logs and artifacts into a tar.gz for forensic analysis.
utmp
The file /run/utmp listing the sessions open right now, in the same struct utmp format as wtmp; cleared at every boot.
wtmp and btmp
Binary Linux login records: /var/log/wtmp holds the history of sessions, boots and shutdowns; /var/log/btmp holds failed login attempts.
wtmpdb
The SQLite replacement for wtmp (wtmp.db), with one row per session, times in microseconds and the PAM service name; used by openSUSE and Debian 13.