auth.log, secure and syslog: Linux Text Logs
rsyslog text logs on Linux: auth.log and syslog on Debian/Ubuntu, secure and messages on RHEL, with rotation and timestamp format pitfalls.
- Location
- /var/log/auth.log, /var/log/secure
- Distributions
- Proves
- Who authenticated, from where, with which method, and what services and the kernel reported, in plain text
- Timestamps
- Traditional: local time, no year or zone. RFC 3339: local time with offset and microseconds
- Access
- root or adm group (Debian/Ubuntu); root (RHEL)
- Retention
- logrotate: weekly, 4 generations on Debian/Ubuntu and RHEL defaults
- Collection
- UAC, Velociraptor, cp -a, tar
Tools
Compare all tools- Linux Log ParserIn browser
- grep / zgrepCLI · built into Linux
- PlasoCLI · open source
- lnavCLI · open source
What it is
A syslog daemon (rsyslog on nearly all mainstream distributions, sometimes syslog-ng) receives messages from programs and the kernel and writes them to text files according to facility and priority rules. On systemd hosts rsyslog usually reads from journald, so the text files and the journal hold overlapping copies of the same events, stored and rotated independently.
The authentication file is the backbone of most intrusion timelines: sshd logins and failures, sudo and su use, PAM session open/close, account creation and password changes all land there through the auth and authpriv facilities.
Where it lives
| Content | Debian / Ubuntu | RHEL / Rocky / Alma / Fedora (rsyslog installed) |
|---|---|---|
Authentication (auth, authpriv) | /var/log/auth.log | /var/log/secure |
| General messages | /var/log/syslog | /var/log/messages |
| Kernel | /var/log/kern.log | in /var/log/messages |
| Cron | in /var/log/syslog | /var/log/cron |
/var/log/mail.log | /var/log/maillog | |
| Rules | /etc/rsyslog.conf, /etc/rsyslog.d/50-default.conf (Ubuntu) | /etc/rsyslog.conf, /etc/rsyslog.d/ |
| Rotation | /etc/logrotate.d/rsyslog | /etc/logrotate.conf, /etc/logrotate.d/rsyslog (older releases: syslog) |
The RHEL defaults send authpriv.* to secure and *.info;mail.none;authpriv.none;cron.none to messages. Ubuntu's 50-default.conf sends auth,authpriv.* to auth.log and everything except auth to syslog.
Not every host has these files. Debian 12 no longer installs rsyslog by default and Fedora stopped doing so in Fedora 20, so a fresh install may log only to the journal. Upgraded systems keep rsyslog. Check for /etc/rsyslog.conf and the rsyslog package before treating an absent file as deletion.
What it proves
- Successful and failed SSH authentication, with user, source IP, port and method (
Accepted password,Accepted publickey ... SHA256:<fingerprint>,Failed password,Invalid user). - Privilege use:
sudo:command lines,su:sessions,pam_unix(...:session): session opened for user. - Account changes:
useradd,usermod,groupadd,passwdandchpasswdmessages. - Service and kernel events in
syslog/messages/kern.log: service restarts, USB attach, firewall LOG lines. - It does not prove what a user did after logging in, and anything written through
loggerby a local user looks like a normal line. Program name and PID in the line come from the sender and are not verified.
Key fields
A traditional (RFC 3164 style) line:
Sep 20 03:14:07 web-prod-03 sshd[4190]: Accepted password for deploy from 203.0.113.50 port 40318 ssh2
The same line in rsyslog's high-precision default format (RFC 3339 timestamp):
2026-09-20T03:14:07.512345+02:00 web-prod-03 sshd[4190]: Accepted password for deploy from 203.0.113.50 port 40318 ssh2
| Part | Meaning |
|---|---|
| Timestamp | Time the syslog daemon wrote the line (see below) |
| Hostname | Host that generated the message (important on central log servers) |
Tag program[pid] | Sender name and PID as supplied by the sender |
| Message | Free text; patterns are program specific |
Useful message patterns: Accepted, Failed password, Invalid user, Connection closed by authenticating user, session opened, session closed, COMMAND=, new user:, new group:, password changed for. OpenSSH 9.8 and later split the per-connection process into sshd-session, so grep for both names.
Timestamps
Two formats are common, and you must identify which one the host used:
- Traditional (
RSYSLOG_TraditionalFileFormat):Mmm dd HH:MM:SS, local time, no year, no time zone. The RHEL-familyrsyslog.confsets this template explicitly. - High precision (rsyslog's built-in default
RSYSLOG_FileFormat): RFC 3339 with microseconds and UTC offset. Debian enabled it from bookworm (12) by no longer forcing the traditional template, and Ubuntu 24.04 logs this way too.
For the traditional format, recover the zone from /etc/localtime (or /etc/timezone on Debian) in the image, and infer the year from file metadata and rotation order. Watch for year rollovers inside a single file and DST shifts that duplicate or skip an hour.
ls -l /mnt/evidence/etc/localtime # symlink target names the zone
TZ=Europe/Paris date -u -d '2026-09-20 03:14:07' # local -> UTC
Retention
logrotate controls lifetime. Debian's /etc/logrotate.d/rsyslog rotates weekly, keeps 4 generations, and compresses with delaycompress (auth.log, auth.log.1, auth.log.2.gz ...). RHEL defaults are weekly, rotate 4 and dateext (secure-20260920). Expect roughly a month of text history unless the configuration was changed. The journal may retain more or less, so always compare both.
Collection
# Dead box, from a read-only mount
tar -C /mnt/evidence -cpf /cases/2026-017/varlog.tar var/log etc/rsyslog.conf etc/rsyslog.d etc/logrotate.conf etc/logrotate.d etc/localtime
# Live, as root: copy, do not tail or edit in place
tar -C / -cpf /media/ir/varlog.tar var/log etc/rsyslog.conf etc/rsyslog.d etc/logrotate.d etc/localtime
UAC's var_log artifact collects all of /var/log; Velociraptor can collect the same paths with its file collection artifacts. Take rotated and compressed generations too, and note the collection time: logrotate can fire while you work.
Parsing
Plain text tools go a long way; the key is to read every generation in order.
cd /mnt/evidence/var/log
zgrep -hE 'Accepted|Failed password|Invalid user' auth.log* secure* 2>/dev/null
zgrep -h 'sudo:' auth.log* secure* 2>/dev/null
zgrep -hE 'new user|new group|password changed' auth.log* secure* 2>/dev/null
For timelines, Plaso ships the text/syslog and text/syslog_traditional parser plugins; pass --timezone for traditional-format files so the local times are converted correctly. lnav is convenient for interactive browsing of many rotated files. Linux Log Parser reads auth.log / secure, syslog, journal files, audit.log and wtmp / btmp / lastlog in the browser and merges them into one timeline with rebuilt login sessions; nothing is uploaded.
Investigator tips
- Line counts that drop mid-day, a current file much smaller than its rotated siblings, or a file whose mtime predates known activity are signs of editing or truncation. Compare against the journal and wtmp.
- Every
Acceptedline should pair with a wtmp session and, if auditd runs, aUSER_LOGINrecord in audit.log. A missing partner is worth explaining. - Match
Accepted publickeyfingerprints to entries inauthorized_keys(see SSH artifacts) to identify the key used. - Check
/etc/rsyslog.confand/etc/rsyslog.d/for forwarding targets (@host,@@host,omfwd): a remote collector may still hold logs removed locally, and a newly addedstopor discard rule is itself tampering. - A stopped
rsyslog.serviceappears in the journal; a gap in the text log with the journal still running points directly at the syslog daemon. - On central log servers, remember the timestamp may be the receiver's, not the sender's, depending on the template.