Skip to content

Glossary

Journal sequence number (seqnum)

The counter journald assigns to every journal entry, shared by all journal files of a machine; missing numbers reveal entries that no longer exist.

Every entry in a systemd journal file carries a sequence number (seqnum). journald keeps one counter per machine, identified by the seqnum_id stored in each file header, and increments it for every entry it writes, whichever file the entry goes to: system.journal, rotated archives or the per-user user-<UID>.journal files. Each header also records head_entry_seqnum and tail_entry_seqnum, the first and last numbers the file should contain.

Why it matters in investigations

Sorted by seqnum within one seqnum_id, the entries of a complete collection form a continuous series. A missing range means entries existed that are not in the files you have. That makes the seqnum built-in tamper evidence: deleting a whole journal file, or rewriting one without some entries, leaves a hole that remains visible after the entries are gone.

Rule out the benign causes first:

  • User journals not collected. Entries written to user-1001.journal consume numbers too; if only system.journal was taken, each of them appears as a gap.
  • Vacuumed archives. Retention and journalctl --vacuum-* delete old files, so the gap sits at the start of the range.
  • Live collection. A gap at the very end can simply be entries written while you copied.

A gap in the middle of the incident window, with user journals present, or one that lines up with an rm of a journal file in audit.log, is a finding.

Example

journalctl -D /mnt/evidence/var/log/journal --header

For each file this prints the sequence number ID and the head and tail sequence numbers. If system.journal jumps from one number to a much higher one during the incident and no user-1001.journal was found, the missing entries were probably in that user file. A clock set backwards shows up as realtime going down while seqnum keeps going up.

Linux Log Parser reports seqnum gaps and warns when no user journal was loaded. See detecting log tampering.