Skip to content

Glossary

systemd-logind

The systemd login manager, which numbers user sessions and logs New session N of user X and Removed session N.

systemd-logind is the systemd service that manages user logins. When a login service opens a PAM session, the pam_systemd module registers it with logind, which gives the session a number, creates a scope unit for its processes (session-7.scope) and starts the user's service manager (user@1001.service) if it is not already running. loginctl list-sessions shows the sessions on a live host.

logind announces each step in the journal and, through rsyslog, in auth.log: New session 7 of user svc_backup. at login, then Session 7 logged out. Waiting for processes to exit. and Removed session 7. at the end.

Why it matters in investigations

A single SSH login produces three different identifiers: the sshd PID in auth.log, the logind session number, and the audit session ses in audit.log. They are unrelated numbers, but they are created within milliseconds of each other, so a session can be rebuilt across sources by time and user. The logind number is the link to the journal: processes started in the session run inside session-7.scope, and their journal entries carry the trusted field _SYSTEMD_SESSION=7. The user manager matters too: a systemd user service installed by an intruder is started by systemd[PID] running as that user, which is how user-level persistence appears in syslog and the journal. A session with a New session line but no Removed session may still have been open at collection time, or the host may have crashed.

Example

2026-09-14T10:02:11.482113+00:00 fin-jump-01 sshd[3071]: Accepted password for svc_backup from 203.0.113.45 port 51544 ssh2
2026-09-14T10:02:11.491113+00:00 fin-jump-01 sshd[3071]: pam_unix(sshd:session): session opened for user svc_backup(uid=1001) by svc_backup(uid=0)
2026-09-14T10:02:11.494113+00:00 fin-jump-01 systemd-logind[845]: New session 7 of user svc_backup.

sshd PID 3071, logind session 7 and, in audit.log, ses=114 all describe the same login.

  • pam_unix: the session line logged just before.
  • auid: the audit session of the same login.
  • systemd journal: where _SYSTEMD_SESSION is recorded.

Linux Log Parser merges these identifiers into one session. See the pillar guide.