Glossary
systemd-logind
The systemd login manager, which numbers user sessions and logs New session N of user X and Removed session N.
systemd-logind is the systemd service that manages user logins. When a login service opens a PAM session, the pam_systemd module registers it with logind, which gives the session a number, creates a scope unit for its processes (session-7.scope) and starts the user's service manager (user@1001.service) if it is not already running. loginctl list-sessions shows the sessions on a live host.
logind announces each step in the journal and, through rsyslog, in auth.log: New session 7 of user svc_backup. at login, then Session 7 logged out. Waiting for processes to exit. and Removed session 7. at the end.
Why it matters in investigations
A single SSH login produces three different identifiers: the sshd PID in auth.log, the logind session number, and the audit session ses in audit.log. They are unrelated numbers, but they are created within milliseconds of each other, so a session can be rebuilt across sources by time and user. The logind number is the link to the journal: processes started in the session run inside session-7.scope, and their journal entries carry the trusted field _SYSTEMD_SESSION=7. The user manager matters too: a systemd user service installed by an intruder is started by systemd[PID] running as that user, which is how user-level persistence appears in syslog and the journal. A session with a New session line but no Removed session may still have been open at collection time, or the host may have crashed.
Example
2026-09-14T10:02:11.482113+00:00 fin-jump-01 sshd[3071]: Accepted password for svc_backup from 203.0.113.45 port 51544 ssh2
2026-09-14T10:02:11.491113+00:00 fin-jump-01 sshd[3071]: pam_unix(sshd:session): session opened for user svc_backup(uid=1001) by svc_backup(uid=0)
2026-09-14T10:02:11.494113+00:00 fin-jump-01 systemd-logind[845]: New session 7 of user svc_backup.
sshd PID 3071, logind session 7 and, in audit.log, ses=114 all describe the same login.
Related terms
- pam_unix: the session line logged just before.
- auid: the audit session of the same login.
- systemd journal: where
_SYSTEMD_SESSIONis recorded.
Linux Log Parser merges these identifiers into one session. See the pillar guide.