Glossary
Journal sequence number (seqnum)
The counter journald assigns to every journal entry, shared by all journal files of a machine; missing numbers reveal entries that no longer exist.
Every entry in a systemd journal file carries a sequence number (seqnum). journald keeps one counter per machine, identified by the seqnum_id stored in each file header, and increments it for every entry it writes, whichever file the entry goes to: system.journal, rotated archives or the per-user user-<UID>.journal files. Each header also records head_entry_seqnum and tail_entry_seqnum, the first and last numbers the file should contain.
Why it matters in investigations
Sorted by seqnum within one seqnum_id, the entries of a complete collection form a continuous series. A missing range means entries existed that are not in the files you have. That makes the seqnum built-in tamper evidence: deleting a whole journal file, or rewriting one without some entries, leaves a hole that remains visible after the entries are gone.
Rule out the benign causes first:
- User journals not collected. Entries written to
user-1001.journalconsume numbers too; if onlysystem.journalwas taken, each of them appears as a gap. - Vacuumed archives. Retention and
journalctl --vacuum-*delete old files, so the gap sits at the start of the range. - Live collection. A gap at the very end can simply be entries written while you copied.
A gap in the middle of the incident window, with user journals present, or one that lines up with an rm of a journal file in audit.log, is a finding.
Example
journalctl -D /mnt/evidence/var/log/journal --header
For each file this prints the sequence number ID and the head and tail sequence numbers. If system.journal jumps from one number to a much higher one during the incident and no user-1001.journal was found, the missing entries were probably in that user file. A clock set backwards shows up as realtime going down while seqnum keeps going up.
Related terms
- systemd journal: the file format that carries the counter.
- wtmp and btmp: where tampering shows as blanked records instead.
Linux Log Parser reports seqnum gaps and warns when no user journal was loaded. See detecting log tampering.