Glossary
systemd Journal (journald)
The systemd journal is the binary, indexed log store written by systemd-journald, holding structured log entries with trusted metadata fields.
The systemd journal is the log store maintained by systemd-journald. Instead of plain text lines, it keeps structured entries in binary, indexed files. Each entry carries the message plus fields: some supplied by the sender and "trusted" fields prefixed with an underscore that journald adds itself, such as _PID, _UID, _COMM, _EXE, _SYSTEMD_UNIT and _BOOT_ID.
Storage depends on configuration. With the default Storage=auto, logs are persistent in /var/log/journal/<machine-id>/ only if that directory exists; otherwise they live in /run/log/journal/ and are lost at reboot. Active files are named system.journal and user-<uid>.journal; rotated files carry @ suffixes, and files ending in ~ were not closed cleanly.
journalctl --directory=/mnt/evidence/var/log/journal --list-boots
journalctl --directory=/mnt/evidence/var/log/journal _SYSTEMD_UNIT=ssh.service -o json
For forensics, always read a copy with --directory or --file rather than the live host's configuration, and run --verify to check file consistency. Retention limits (SystemMaxUse, MaxRetentionSec) and vacuuming can remove old data, and an attacker with root can delete or truncate files. See Linux log forensics: syslog and journald.