Skip to content

Glossary

auid (audit login UID)

The audit login UID: the UID a user logged in with, set once at login and kept by every child process, including through sudo and su.

The auid (audit login UID, also called loginuid) is the UID a user logged in with. The kernel stores it per process, together with the audit session ID ses, when a login service such as sshd, login or cron opens a PAM session; on most distributions the pam_loginuid module writes it to /proc/self/loginuid. From then on every child process inherits both values, and they do not change when a process switches user with sudo, su or a setuid program.

The value 4294967295 (the 32-bit form of -1) means unset: daemons and processes started at boot never had a login, so their records carry auid=4294967295 and ses=4294967295. ausearch -i prints this as unset.

Why it matters in investigations

Once an intruder runs sudo -i, auth.log only shows the shell being opened; commands typed inside it are not logged there. auditd records still name the original account, because uid and euid change to 0 while auid stays on the login user. That is what makes commands run as root attributable to a person or a compromised service account. The systemd journal stores the same values as _AUDIT_LOGINUID and _AUDIT_SESSION, which links journal entries to the audit session.

Example

A command run in a root shell opened by UID 1001:

type=SYSCALL msg=audit(1789381120.086:181322): arch=c000003e syscall=59 success=yes exit=0 ppid=3200 pid=3204 auid=1001 uid=0 gid=0 euid=0 tty=pts1 ses=114 comm="tar" exe="/usr/bin/tar" key="exec"

uid=0 says root ran tar; auid=1001 says it happened in the login of UID 1001, and ses=114 ties it to one session. To list everything under that login: ausearch -if audit.log -ul 1001 -i.

Linux Log Parser uses auid and ses to attach root commands to rebuilt sessions. Walkthrough: auditd EXECVE forensics.