Skip to content

Glossary

systemd journal

The binary log of systemd-journald: structured FIELD=value entries with trusted sender fields and microsecond UTC timestamps, often the only system log.

The systemd journal is the binary log written by systemd-journald. It collects messages from the kernel, from programs using the syslog API or the native journal API, from the standard output of every service, and from the audit subsystem, and stores them as entries made of FIELD=value pairs. Persistent files live in /var/log/journal/<machine-id>/; volatile ones in /run/log/journal/<machine-id>/ disappear at reboot. Which one is used depends on Storage= in journald.conf.

Each file starts with the signature LPKSHHRH and a header, followed by objects: deduplicated DATA payloads, ENTRY objects, hash tables and arrays. Large payloads can be compressed with XZ, LZ4 or ZSTD, and since systemd 252 files may use a compact layout with 32-bit offsets.

Why it matters in investigations

Fields starting with an underscore are added by journald from the kernel's view of the sender and cannot be forged by it: _PID, _UID, _COMM, _EXE, _CMDLINE, _SYSTEMD_UNIT, _BOOT_ID, _AUDIT_LOGINUID, _AUDIT_SESSION. A fake sshd line written with logger still shows _COMM=logger and the real UID. Timestamps are microseconds since the epoch in UTC, and every entry has a sequence number that exposes deleted entries. On Debian 12 and some Fedora installs, the journal is the only system log.

Example

An SSH login as shown by journalctl -o verbose (abridged):

_TRANSPORT=syslog
_PID=3071
_UID=0
_COMM=sshd
_SYSTEMD_UNIT=ssh.service
SYSLOG_IDENTIFIER=sshd
MESSAGE=Accepted password for svc_backup from 203.0.113.45 port 51544 ssh2

Always pass -D when reading evidence, for example journalctl -D /mnt/evidence/var/log/journal, otherwise journalctl reads the analysis host's own journal. Keep .journal~ files: they were renamed after an unclean stop and often cover the last minutes before a crash.

Linux Log Parser parses raw journal files, compact and compressed. See systemd journal forensics.