Glossary
rsyslog
The syslog daemon on most Linux distributions, which writes text logs such as auth.log, syslog, secure and messages, usually fed by journald.
rsyslog is the syslog daemon shipped by most Linux distributions. It receives messages from local programs, the kernel and the network, and routes them by facility and priority to text files, remote servers or other outputs. Rules live in /etc/rsyslog.conf and /etc/rsyslog.d/*.conf; the files it writes are rotated by logrotate, not by rsyslog itself, which produces generations such as auth.log.1 and auth.log.2.gz (Debian, Ubuntu) or dated ones such as secure-20260913 (RHEL family).
On systemd hosts rsyslog is usually fed by journald, either by reading the journal (the imjournal module, common on the RHEL family) or through the syslog socket journald forwards to. The text logs and the journal therefore hold overlapping copies of the same messages, written and rotated independently.
Why it matters in investigations
That overlap is useful. A line present in the journal but missing from auth.log, over a period both cover, means the text file was edited, typically with sed -i or a cleaner that only knows text files. The reverse usually means the journal did not keep that period. When counting brute-force attempts, deduplicate: each sshd line exists twice. Also check that rsyslog was running at all: Debian 12 and some Fedora installs no longer install it, so a missing auth.log is not proof of deletion, and rsyslog.service stopping outside a reboot is worth explaining.
Example
Typical routing rules:
auth,authpriv.* /var/log/auth.log # Debian, Ubuntu
authpriv.* /var/log/secure # RHEL, Rocky, Alma, Fedora
The template decides the timestamp: RSYSLOG_TraditionalFileFormat writes RFC 3164 style local times without a year, while the default file format writes RFC 3339 timestamps with an offset.
Related terms
- systemd journal: the usual source of rsyslog's messages.
- pam_unix: the module behind most auth.log lines.
- RFC 5424: the format used when forwarding.
Linux Log Parser marks auth.log lines that the journal also holds. See auth.log forensics.