Skip to content

LogsUser activityNetwork

auth.log, secure and syslog: Linux Text Logs

rsyslog text logs on Linux: auth.log and syslog on Debian/Ubuntu, secure and messages on RHEL, with rotation and timestamp format pitfalls.

Location
/var/log/auth.log, /var/log/secure
Proves
Who authenticated, from where, with which method, and what services and the kernel reported, in plain text
Timestamps
Traditional: local time, no year or zone. RFC 3339: local time with offset and microseconds
Access
root or adm group (Debian/Ubuntu); root (RHEL)
Retention
logrotate: weekly, 4 generations on Debian/Ubuntu and RHEL defaults
Collection
UAC, Velociraptor, cp -a, tar

What it is

A syslog daemon (rsyslog on nearly all mainstream distributions, sometimes syslog-ng) receives messages from programs and the kernel and writes them to text files according to facility and priority rules. On systemd hosts rsyslog usually reads from journald, so the text files and the journal hold overlapping copies of the same events, stored and rotated independently.

The authentication file is the backbone of most intrusion timelines: sshd logins and failures, sudo and su use, PAM session open/close, account creation and password changes all land there through the auth and authpriv facilities.

Where it lives

ContentDebian / UbuntuRHEL / Rocky / Alma / Fedora (rsyslog installed)
Authentication (auth, authpriv)/var/log/auth.log/var/log/secure
General messages/var/log/syslog/var/log/messages
Kernel/var/log/kern.login /var/log/messages
Cronin /var/log/syslog/var/log/cron
Mail/var/log/mail.log/var/log/maillog
Rules/etc/rsyslog.conf, /etc/rsyslog.d/50-default.conf (Ubuntu)/etc/rsyslog.conf, /etc/rsyslog.d/
Rotation/etc/logrotate.d/rsyslog/etc/logrotate.conf, /etc/logrotate.d/rsyslog (older releases: syslog)

The RHEL defaults send authpriv.* to secure and *.info;mail.none;authpriv.none;cron.none to messages. Ubuntu's 50-default.conf sends auth,authpriv.* to auth.log and everything except auth to syslog.

Not every host has these files. Debian 12 no longer installs rsyslog by default and Fedora stopped doing so in Fedora 20, so a fresh install may log only to the journal. Upgraded systems keep rsyslog. Check for /etc/rsyslog.conf and the rsyslog package before treating an absent file as deletion.

What it proves

  • Successful and failed SSH authentication, with user, source IP, port and method (Accepted password, Accepted publickey ... SHA256:<fingerprint>, Failed password, Invalid user).
  • Privilege use: sudo: command lines, su: sessions, pam_unix(...:session): session opened for user.
  • Account changes: useradd, usermod, groupadd, passwd and chpasswd messages.
  • Service and kernel events in syslog/messages/kern.log: service restarts, USB attach, firewall LOG lines.
  • It does not prove what a user did after logging in, and anything written through logger by a local user looks like a normal line. Program name and PID in the line come from the sender and are not verified.

Key fields

A traditional (RFC 3164 style) line:

Sep 20 03:14:07 web-prod-03 sshd[4190]: Accepted password for deploy from 203.0.113.50 port 40318 ssh2

The same line in rsyslog's high-precision default format (RFC 3339 timestamp):

2026-09-20T03:14:07.512345+02:00 web-prod-03 sshd[4190]: Accepted password for deploy from 203.0.113.50 port 40318 ssh2
PartMeaning
TimestampTime the syslog daemon wrote the line (see below)
HostnameHost that generated the message (important on central log servers)
Tag program[pid]Sender name and PID as supplied by the sender
MessageFree text; patterns are program specific

Useful message patterns: Accepted, Failed password, Invalid user, Connection closed by authenticating user, session opened, session closed, COMMAND=, new user:, new group:, password changed for. OpenSSH 9.8 and later split the per-connection process into sshd-session, so grep for both names.

Timestamps

Two formats are common, and you must identify which one the host used:

  • Traditional (RSYSLOG_TraditionalFileFormat): Mmm dd HH:MM:SS, local time, no year, no time zone. The RHEL-family rsyslog.conf sets this template explicitly.
  • High precision (rsyslog's built-in default RSYSLOG_FileFormat): RFC 3339 with microseconds and UTC offset. Debian enabled it from bookworm (12) by no longer forcing the traditional template, and Ubuntu 24.04 logs this way too.

For the traditional format, recover the zone from /etc/localtime (or /etc/timezone on Debian) in the image, and infer the year from file metadata and rotation order. Watch for year rollovers inside a single file and DST shifts that duplicate or skip an hour.

ls -l /mnt/evidence/etc/localtime        # symlink target names the zone
TZ=Europe/Paris date -u -d '2026-09-20 03:14:07'   # local -> UTC

Retention

logrotate controls lifetime. Debian's /etc/logrotate.d/rsyslog rotates weekly, keeps 4 generations, and compresses with delaycompress (auth.log, auth.log.1, auth.log.2.gz ...). RHEL defaults are weekly, rotate 4 and dateext (secure-20260920). Expect roughly a month of text history unless the configuration was changed. The journal may retain more or less, so always compare both.

Collection

# Dead box, from a read-only mount
tar -C /mnt/evidence -cpf /cases/2026-017/varlog.tar var/log etc/rsyslog.conf etc/rsyslog.d etc/logrotate.conf etc/logrotate.d etc/localtime

# Live, as root: copy, do not tail or edit in place
tar -C / -cpf /media/ir/varlog.tar var/log etc/rsyslog.conf etc/rsyslog.d etc/logrotate.d etc/localtime

UAC's var_log artifact collects all of /var/log; Velociraptor can collect the same paths with its file collection artifacts. Take rotated and compressed generations too, and note the collection time: logrotate can fire while you work.

Parsing

Plain text tools go a long way; the key is to read every generation in order.

cd /mnt/evidence/var/log
zgrep -hE 'Accepted|Failed password|Invalid user' auth.log* secure* 2>/dev/null
zgrep -h 'sudo:' auth.log* secure* 2>/dev/null
zgrep -hE 'new user|new group|password changed' auth.log* secure* 2>/dev/null

For timelines, Plaso ships the text/syslog and text/syslog_traditional parser plugins; pass --timezone for traditional-format files so the local times are converted correctly. lnav is convenient for interactive browsing of many rotated files. Linux Log Parser reads auth.log / secure, syslog, journal files, audit.log and wtmp / btmp / lastlog in the browser and merges them into one timeline with rebuilt login sessions; nothing is uploaded.

Investigator tips

  • Line counts that drop mid-day, a current file much smaller than its rotated siblings, or a file whose mtime predates known activity are signs of editing or truncation. Compare against the journal and wtmp.
  • Every Accepted line should pair with a wtmp session and, if auditd runs, a USER_LOGIN record in audit.log. A missing partner is worth explaining.
  • Match Accepted publickey fingerprints to entries in authorized_keys (see SSH artifacts) to identify the key used.
  • Check /etc/rsyslog.conf and /etc/rsyslog.d/ for forwarding targets (@host, @@host, omfwd): a remote collector may still hold logs removed locally, and a newly added stop or discard rule is itself tampering.
  • A stopped rsyslog.service appears in the journal; a gap in the text log with the journal still running points directly at the syslog daemon.
  • On central log servers, remember the timestamp may be the receiver's, not the sender's, depending on the template.

See also