Glossary
EXECVE record
The audit.log record that holds the arguments of an executed program, argc and a0..aN, with hex encoding for arguments containing spaces or special characters.
An EXECVE record is the audit.log record that holds the argument list of an executed program. When an auditd rule audits the execve syscall, each execution produces several records sharing the same msg=audit(sec.msec:serial) stamp: SYSCALL (who ran it, with auid, uid, ses and exe), EXECVE (argc and one field a0, a1… per argument), CWD (the working directory), one or more PATH records and PROCTITLE, ended by EOE.
Argument values come in three forms. Values in double quotes are plain text. Unquoted values are hex-encoded because the argument contains a space, a double quote, a control character or non-ASCII bytes. Long arguments are split into aN_len= followed by aN[0]=, aN[1]=… chunks, and a very long command line can span several EXECVE records of the same event.
Why it matters in investigations
The EXECVE record is the most precise command-line evidence on a Linux host. It captures commands typed in a root shell, which auth.log never sees, and it removes ambiguity: the sudo line in auth.log shows /srv/finance/Q3 close without telling you whether that is one argument or two, while the hex encoding in EXECVE settles it. PROCTITLE also holds the command line but is truncated by the kernel for long ones, so prefer EXECVE when both exist.
Example
type=EXECVE msg=audit(1789381120.086:181322): argc=4 a0="tar" a1="czf" a2="/tmp/.f.tgz" a3=2F7372762F66696E616E63652F513320636C6F7365
a3 decodes to /srv/finance/Q3 close, a single argument with a space. Group records by the whole stamp, not by the serial alone, since the serial restarts at boot.
Related terms
Linux Log Parser reassembles hex and chunked arguments automatically. More in auditd EXECVE forensics.