Chuleta de artefactos de Linux
Todos los artefactos en una sola tabla, agrupados por categoría. Imprime en horizontal o guarda como PDF desde el navegador.
www.linuxforensics.app/es/artifacts
Los artefactos más usados están traducidos. Las entradas marcadas «Inglés» abren la página en inglés.
| Artefacto | Ubicación | Prueba | Marcas de tiempo | Acceso | Retención | Análisis |
|---|---|---|---|---|---|---|
| Ejecución | ||||||
| /tmp, /var/tmp and /dev/shmInglésDebian · RHEL · SUSE · Arch | /tmp, /var/tmp, /dev/shm, /run/user/<uid> | That files were dropped or run from world-writable locations, by which user and when | Inode times (mtime, ctime, atime, birth where supported) in the filesystem's native precision; tmpfs keeps them in RAM only | Any user can write; root needed to read other users' files (mode 1777 with sticky bit) | tmpfs: lost at reboot; disk: until cleaned by systemd-tmpfiles ages (upstream 10 days /tmp, 30 days /var/tmp) or deleted | find, stat, debugfs, The Sleuth Kit, Velociraptor |
| Artefactos en vivo de /procDebian · RHEL · SUSE · Arch | /proc/<pid>/ | Qué se está ejecutando ahora mismo, desde qué binario, con qué argumentos, archivos y conexiones de red | Sin marcas de tiempo de archivo útiles; hora de inicio del proceso en ticks de reloj desde el arranque (/proc/<pid>/stat campo 22) | root para ver exe, environ, fd y maps de todos los procesos; los demás usuarios solo ven los suyos | Volátil: desaparece al terminar el proceso o al reiniciar | ps, ss, lsof, Velociraptor, Volatility 3 |
| Docker, containerd and Podman Artifacts on Linux HostsInglésDebian · RHEL · SUSE · Arch | /var/lib/docker/containers/<id>/ | Which containers ran, from which image and command, with which privileges, what they printed and which files they changed | RFC 3339 UTC with nanoseconds in config and log JSON; filesystem times in overlay layers | root (or docker group, which is root-equivalent); rootless Podman data is owned by the user | Until the container is removed (docker rm, pod deletion); logs unbounded unless max-size/max-file set | container-explorer, jq, docker, crictl, ctr |
| Historial de la shellDebian · RHEL · SUSE · Arch | ~/.bash_history | Qué comandos se teclearon en una shell interactiva que se ejecutaba con una cuenta determinada, y a veces cuándo | Segundos de época Unix (UTC) cuando se registran: bash solo con HISTTIMEFORMAT, zsh con EXTENDED_HISTORY, fish siempre | Cualquier usuario para sus propios archivos; root para los directorios personales de otros usuarios | Hasta que HISTFILESIZE/SAVEHIST lo recortan o se borra | Plaso, Volatility 3, Velociraptor |
| Linux Crash Reports and Core DumpsInglésDebian · RHEL · SUSE · Arch | /var/lib/systemd/coredump/, /var/crash/ | Which program crashed, when, as which user, with which command line, and what its memory held at that moment | Journal: UTC microseconds; core file names: epoch microseconds; apport Date: local asctime | root; per-user cores readable by the owning user through coredumpctl | systemd-coredump: 3 days (systemd before 256) or 2 weeks (256+), size caps; apport: 7 days | coredumpctl, gdb, getfattr, apport-unpack, crash |
| Linux Memory AcquisitionInglésDebian · RHEL · SUSE · Arch | /proc/kcore, /dev/crash, /dev/mem | Running processes, network connections, loaded modules and hidden code at capture time, including what disk and /proc do not show | Capture time from your case log; in-memory structures carry their own times (process start as time since boot) | root; blocked or limited by kernel lockdown, module signature enforcement and CONFIG_STRICT_DEVMEM | Volatile: lost at power-off; changes continuously while the host runs | Volatility 3, dwarf2json, AVML, LiME |
| Logs de sudoDebian · RHEL · SUSE · Arch | /var/log/auth.log, /var/log/secure | Qué cuenta ejecutó qué comando como qué usuario de destino, desde qué terminal y directorio, y los intentos fallidos | Hora de syslog/journal del host (ver formatos de syslog); los logs de E/S guardan tiempos relativos por sesión | root (o grupo adm para auth.log en Debian/Ubuntu) | Sigue la rotación de auth.log/secure y los límites del journal; logs de E/S hasta su borrado | grep/zgrep, journalctl, sudoreplay, ausearch, Plaso |
| Snap and Flatpak ArtifactsInglésDebian · RHEL · SUSE · Arch | /var/lib/snapd/, /snap/, ~/snap/; /var/lib/flatpak/, ~/.local/share/flatpak/, ~/.var/app/ | Which sandboxed applications were installed, refreshed or removed, from which store or remote, whether any were sideloaded, and where each app kept its user data | RFC 3339 times with zone in snapd state.json; journal UTC entries for Flatpak history; directory and deployment file times | root for /var/lib/snapd/state.json; world-readable Flatpak system installation; user data owned by each user | Installed apps and data persist until removal; snapd prunes old change records; Flatpak history lasts as long as the journal | snap, flatpak, jq, journalctl, find |
| Persistencia | ||||||
| /etc/ld.so.preload y LD_PRELOADDebian · RHEL · SUSE · Arch | /etc/ld.so.preload | Si se forzó la carga de una biblioteca compartida en los procesos enlazados dinámicamente, cuál y desde cuándo | mtime/ctime/crtime del archivo de precarga y de la biblioteca; sin marcas de tiempo internas | root para escribir; legible por todos; el propio rootkit puede ocultarlo a las herramientas en vivo | Hasta su borrado; LD_PRELOAD en el entorno de un proceso dura hasta que el proceso termina | debugfs, UAC, Volatility 3, Velociraptor |
| /etc/passwd, shadow and groupInglésDebian · RHEL · SUSE · Arch | /etc/passwd, /etc/shadow, /etc/group, /etc/gshadow | Which local accounts and group memberships exist, which can log in, and when each password was last changed | shadow: days since 1970-01-01 UTC; files: inode mtime/ctime; logs: syslog/journal time | passwd and group: any user; shadow and gshadow: root | Until changed; one backup generation (passwd-, shadow-, group-, gshadow-) | awk, pwck -r, grpck -r, Velociraptor, ausearch |
| Artefactos SSHDebian · RHEL · SUSE · Arch | ~/.ssh/authorized_keys | Qué claves pueden iniciar sesión en una cuenta, a dónde se conectó un usuario y quién inició sesión por SSH y desde dónde | Archivos de claves: solo marcas de tiempo del sistema de archivos; logs: hora local de syslog o usec del journal desde la época Unix (UTC) | root (o el titular de la cuenta para su propio ~/.ssh); grupo adm/systemd-journal para los logs | Archivos de claves hasta su borrado; las líneas de log siguen la rotación de syslog y los límites del journal | ssh-keygen, Velociraptor, UAC, grep |
| Cron, anacron, at y timers de systemd en LinuxDebian · RHEL · SUSE · Arch | /var/spool/cron/ | Qué comandos se programaron, con qué cuenta, y cuándo los lanzó por última vez cron, anacron o un timer | mtime/ctime de los archivos; hora de syslog o del journal para las ejecuciones; sellos de anacron como fecha local YYYYMMDD | root para todos los directorios de spool; cualquier usuario para su propio crontab con crontab -l | Hasta su borrado; las evidencias de ejecución siguen la rotación de syslog/journal | Velociraptor, UAC, grep, systemctl |
| eBPF Programs and Pinned MapsInglésDebian · RHEL · SUSE · Arch | Kernel memory (bpftool prog/map/link), /sys/fs/bpf/ (pinned objects), loader binaries and .o files on disk | Which eBPF programs are attached to the kernel, what they hook, who loaded them and when, and which on-disk loader restores them | bpftool loaded_at (wall clock) per program; audit BPF records (kernel 5.8+); loader file times | root (CAP_BPF / CAP_SYS_ADMIN) to list programs; kernel.unprivileged_bpf_disabled usually blocks others | Programs live until unloaded or reboot; pins in /sys/fs/bpf vanish at reboot; loaders persist on disk | bpftool, Volatility 3, ss, ausearch, readelf, find |
| Linux Kernel ModulesInglésDebian · RHEL · SUSE · Arch | /proc/modules | Which kernel modules are loaded or set to load at boot, and whether unsigned or out-of-tree code entered the kernel | Kernel log in seconds since boot (dmesg) or journal usec since Unix epoch (UTC); config file times | root; kernel addresses in /proc/modules are zeroed for unprivileged readers | Loaded state and taint until reboot; config files until deleted; log lines per journal/syslog limits | Volatility 3, modinfo, Velociraptor, UAC |
| PAM Configuration and ModulesInglésDebian · RHEL · SUSE · Arch | /etc/pam.d/, /usr/lib64/security/ (RHEL, SUSE), /usr/lib/x86_64-linux-gnu/security/ (Debian/Ubuntu), /usr/lib/security/ (Arch) | How the host authenticates logins, sudo and su, and whether that chain was altered to accept a backdoor password or capture credentials | File system times of stack files and modules; PAM messages in auth logs and the journal | root to modify; configuration world-readable, modules readable by all | Persistent until changed; package updates may overwrite a patched module | rpm, dpkg, debsums, authselect, find, grep / zgrep, strings |
| rc.local, SysV init.d and MOTD ScriptsInglésDebian · RHEL | /etc/rc.local | Whether a script was set to run as root at boot or at every login, and when it was placed there | File mtime/ctime/crtime only; execution times from journal or syslog | root to write; world-readable on most systems | Until deleted; execution evidence follows journal/syslog rotation | UAC, Velociraptor, grep, journalctl |
| Shell Startup FilesInglésDebian · RHEL · SUSE · Arch | /etc/profile.d/ | Whether code was set to run automatically each time a user or root starts or ends a shell session | None inside the files; use inode mtime/ctime/crtime (ext4, XFS v5) | root for /etc files; any user for own dotfiles; root to read other users' homes | Until modified or deleted; package upgrades may replace /etc defaults | Velociraptor, debsums, rpm -V |
| SUID, SGID and File CapabilitiesInglésDebian · RHEL · SUSE · Arch | Inode mode bits (04000, 02000) and the security.capability extended attribute, anywhere on the file system | Which executables run with elevated privileges regardless of who starts them, and whether any were added or altered outside the package manager | Setting a bit or capability updates the inode ctime only; mtime and birth time come from the copy or install | Readable by any user with stat/getcap; root to set | Persistent until the file is replaced or the bit removed; package updates reset package-owned files | find, getcap, getfattr, stat, rpm, dpkg, debsums |
| sysctl, Boot Parameters and binfmt_misc on LinuxInglésDebian · RHEL · SUSE · Arch | /etc/sysctl.conf, /etc/sysctl.d/, /usr/lib/sysctl.d/, /proc/sys/ (live), /proc/cmdline, /etc/default/grub, /etc/binfmt.d/ | Which kernel security settings were weakened, and whether a kernel callback (core_pattern, modprobe, binfmt_misc) was pointed at attacker code | File system times of configuration files only; live values carry no timestamp | root to change; most values world-readable in /proc/sys | Files persist; runtime changes via sysctl -w or /proc/sys writes are lost at reboot | sysctl, systemd-analyze, find, grep / zgrep, rpm, dpkg |
| Unidades systemdDebian · RHEL · SUSE · Arch | /etc/systemd/system/ | Qué servicios y timers están configurados para arrancar, qué ejecutan y cuándo se instaló o modificó la unidad | mtime/ctime/crtime de los archivos; entradas del journal en microsegundos desde la época Unix (UTC) | root para las unidades del sistema; cualquier usuario para su propio ~/.config/systemd/user | Hasta su borrado; las unidades de /run se pierden al reiniciar; los eventos de arranque/parada siguen los límites del journal | systemctl, systemd-analyze, Velociraptor, UAC |
| Web Shells in the Web RootInglésDebian · RHEL · SUSE · Arch | /var/www/ (Debian, RHEL Apache), /usr/share/nginx/html (RHEL nginx), /srv/www/htdocs (SUSE), /srv/http (Arch), Tomcat webapps | That a server-side script able to run attacker commands was planted in a served directory, when it was written, by which service account, and what it can do | File system times (birth time on ext4/XFS v5 dates the drop); first request time in access logs | Read as root or the web server account; files usually owned by www-data, apache, nginx, wwwrun or http | Until deleted; deployments and CMS updates may overwrite or remove files | find, grep / zgrep, stat, YARA, php-malware-finder, rpm, dpkg |
| XDG Autostart .desktop EntriesInglésDebian · RHEL · SUSE · Arch | ~/.config/autostart/*.desktop, /etc/xdg/autostart/*.desktop | Which programs were configured to start automatically when a user logs in to a graphical session, and when that configuration was written | File system times only; launches appear in the journal as app-<name>@autostart.service units on systemd-managed sessions | Any user for their own entries; root for /etc/xdg/autostart | Until the .desktop file is deleted; launch records follow journal retention | find, grep / zgrep, journalctl, systemctl, rpm, dpkg |
| Acceso a archivos | ||||||
| Linux Thumbnail CacheInglésDebian · RHEL · SUSE · Arch | ~/.cache/thumbnails/{normal,large,x-large,xx-large,fail}/ | That a user's file manager or file chooser displayed a given image, video or document, where it was stored and what it looked like | Thumb::MTime = source file mtime in Unix seconds; PNG file birth/mtime approximate when the thumbnail was generated | Any user for their own cache (mode 0700 directories, 0600 files); root for other users | Until the cache is cleared; GNOME housekeeping purges thumbnails older than 180 days or beyond 512 MB by default | ExifTool, find, stat |
| Linux TrashInglésDebian · RHEL · SUSE · Arch | ~/.local/share/Trash/{files,info}/ | Which file or folder a user sent to the Trash through a desktop application, from which original path, and when | DeletionDate in local time without a zone (YYYY-MM-DDThh:mm:ss); file system times of the .trashinfo file | Any user for their own Trash (directories mode 0700); root for other users | Until the Trash is emptied or the item restored; optional GNOME auto-purge (off by default, 30 days when enabled) | gio, trash-cli, find, stat |
| Marcas de tiempo de ext4, crtime y archivos borradosDebian · Arch | /dev/<ext4-partition> | Cuándo se creó, modificó, cambió y posiblemente se leyó o borró un archivo, y a veces qué contenía | Segundos de época Unix UTC más nanosegundos en los campos *_extra (inodos de 256 bytes); i_dtime en segundos | Cualquier usuario para stat sobre archivos accesibles; root o acceso al dispositivo en bruto para debugfs y los inodos borrados | Marcas de tiempo hasta que se sobrescriben; inodos y bloques borrados hasta que se reutilizan; el journal es un pequeño log circular | debugfs, The Sleuth Kit, Plaso, ext4magic, stat |
| recently-used.xbelInglésDebian · RHEL · SUSE · Arch | ~/.local/share/recently-used.xbel | Which local or remote files a desktop user opened or saved through GUI applications, with which app and when | ISO 8601 UTC with Z suffix (microseconds when non-zero); legacy app 'timestamp' in Unix seconds | Any user for own file (GTK sets mode 0600); root for other users | GTK default 30 days and 1000 items; GNOME sets recent-files-max-age -1 (keep) by default | xmllint, Python ElementTree |
| Tracker / LocalSearch DBInglésDebian · RHEL · SUSE · Arch | ~/.cache/tracker3/files/ | Which files existed in indexed folders, with name, size, MAC times and extracted metadata as last seen by the indexer | Unix epoch seconds (UTC) as integers, or ISO 8601 text when an offset or sub-second part must be kept | Any user for own cache; root for other users | Mirrors the indexed tree; entries removed when the indexer processes a deletion | tinysparql, sqlite3, localsearch |
| viminfo, ShaDa and lesshstInglésDebian · RHEL · SUSE · Arch | ~/.viminfo | Which files a user opened in vim or Neovim, and what they searched for or ran inside vim and less | Unix epoch seconds in viminfo bar lines and ShaDa entries; none in lesshst | Any user for own files (created mode 0600); root for other users | Until deleted; bounded by the 'viminfo'/'shada' limits and LESSHISTSIZE (default 100) | Plaso, Neovim, python-msgpack |
| XFS ForensicsInglésRHEL · SUSE | /dev/<xfs-volume> | When files were created, modified, changed and read on an XFS volume, and sometimes what deleted files contained | Seconds plus nanoseconds since the Unix epoch, UTC; crtime on v5 inodes; bigtime counter on newer filesystems | Any user for stat on accessible files; root or raw device access for xfs_db | Timestamps until overwritten; deleted inode extents and data blocks until reused | xfs_db, stat, libfsxfs, Plaso |
| Actividad del usuario | ||||||
| Browser Profiles on LinuxInglésDebian · RHEL · SUSE · Arch | ~/.mozilla/firefox/<profile>/places.sqlite | Which sites a user visited, what they downloaded and searched for, and when | Firefox PRTime (usec since 1970 UTC); Chrome/Chromium WebKit time (usec since 1601-01-01 UTC) | Any user for own profile; root for other users | Chrome: visits expire after 90 days; Firefox: size-based expiration of old, low-frecency pages | Hindsight, Plaso, sqlite3 |
| wtmp, btmp, utmp y lastlogDebian · RHEL · SUSE · Arch | /var/log/wtmp | Quién inició sesión, en qué terminal, desde qué host, cuándo terminó la sesión y cuándo se reinició el sistema | Registros utmp: segundos de época Unix + microsegundos (campos de 32 bits), UTC. wtmpdb: microsegundos desde la época | Legibles por todos para wtmp/utmp/lastlog; root (o grupo utmp) para btmp | logrotate: mensual, 1 generación antigua para wtmp y btmp; lastlog hasta que se sobrescribe | last, lastb, utmpdump, wtmpdb, Plaso, Velociraptor |
| Red | ||||||
| /etc/hosts, nsswitch.conf and resolv.conf on LinuxInglésDebian · RHEL · SUSE · Arch | /etc/hosts, /etc/resolv.conf, /etc/nsswitch.conf, /etc/systemd/resolved.conf(.d), NSS modules in the library directory | Where the host sent name lookups, whether names were redirected or blocked locally, and whether an extra NSS module was inserted into user or host lookups | File system times only; systemd-resolved and NetworkManager log DNS server changes to the journal | World-readable; root to modify | Persistent until edited; generated resolv.conf files are rewritten by the network stack | getent, resolvectl, grep / zgrep, rpm, dpkg, journalctl |
| Linux Firewall LogsInglésDebian · RHEL · SUSE · Arch | /var/log/ufw.log, /var/log/kern.log | Which connections the host blocked or logged, from which IPs and ports, and whether firewall rules were changed | Syslog/journal time of the kernel message (journal: UTC microseconds); rule files: file system times | root (or adm group for /var/log files on Debian/Ubuntu) | Follows syslog rotation and journal limits; rule files until changed | grep/zgrep, journalctl, nft, iptables-save, Plaso |
| NetworkManager Profiles and StateInglésDebian · RHEL · SUSE · Arch | /etc/NetworkManager/system-connections/, /var/lib/NetworkManager/ | Which Wi-Fi, wired and VPN profiles existed, when each was last activated, which access points were seen and which IP was leased | Unix epoch seconds (UTC) in timestamps file; journal UTC microseconds; file inode times | root (profiles are root-only 0600); journal: root or systemd-journal group | Profiles until deleted; state files overwritten in place; journal per its limits | grep, journalctl, nmcli (live), Plaso |
| USB y dispositivos | ||||||
| udev and USB Device History on LinuxInglésDebian · RHEL · SUSE · Arch | /etc/udev/rules.d/, /var/log/kern.log | Which USB devices (vendor, product, serial) were attached and when, where storage was mounted, and whether udev rules run code | Journal: UTC microseconds; syslog: host local time; dmesg: seconds since boot | root (or adm/systemd-journal group) for logs; rules readable by any user | Follows journal and kern.log/messages rotation; rules until deleted | journalctl, zgrep, udevadm, Plaso |
| Antiforense | ||||||
| logrotate State and Log GapsInglésDebian · RHEL · SUSE · Arch | /etc/logrotate.conf, /etc/logrotate.d/, state in /var/lib/logrotate/status (Debian) or /var/lib/logrotate/logrotate.status (RHEL) | When each log was last rotated, how many generations should exist, and whether missing, truncated or out-of-pattern log files are explained by rotation or by tampering | State file dates in local time (YYYY-M-D-H:M:S); rotated file mtimes; dateext suffixes | root | Configuration persistent; the state file is rewritten at every run and keeps one line per log | logrotate, stat, find, grep / zgrep, journalctl, systemctl |
| Registros | ||||||
| Apache and Nginx LogsInglésDebian · RHEL | /var/log/apache2/, /var/log/httpd/, /var/log/nginx/ | Which clients requested which URLs, when, with what result and user agent, including exploitation and web shell use | Local time with numeric UTC offset, second precision (default combined format) | root or adm group (Debian/Ubuntu); root (RHEL) | Debian/Ubuntu: daily, 14 kept; RHEL httpd: global weekly, 4 kept; Fedora nginx: daily, 10 kept | grep/zgrep, awk, GoAccess, lnav, Plaso |
| AppArmor and SELinux DenialsInglésDebian · RHEL · SUSE | /var/log/audit/audit.log (with auditd); otherwise kern.log, messages or the journal | Which confined process tried to open, write or execute what and was blocked (or would have been in permissive/complain mode), and when enforcement was switched off | msg=audit(epoch.msec:serial) in UTC; kernel log copies carry syslog or journal time | root (audit.log mode 0600; kernel log readable by adm or root depending on distro) | Follows auditd rotation (upstream 8 MiB x 5) or syslog/journal retention | ausearch, aureport, audit2why, sealert, sestatus, semodule, aa-status, journalctl, grep / zgrep |
| auditd audit.logDebian · RHEL · SUSE | /var/log/audit/audit.log | Qué usuario de inicio de sesión ejecutó qué programa o tocó qué archivo vigilado, y cada autenticación y sesión PAM | Segundos de época Unix con milisegundos en msg=audit(sec.msec:serial), UTC | root (log_group vale root por defecto) | Por tamaño: valor por defecto de upstream 8 MiB x 5 archivos, rotados por auditd | ausearch, aureport, Plaso, Zircolite |
| auth.log, secure y syslogDebian · RHEL | /var/log/auth.log, /var/log/secure | Quién se autenticó, desde dónde y con qué método, y qué notificaron los servicios y el kernel, en texto plano | Tradicional: hora local, sin año ni zona. RFC 3339: hora local con desfase y microsegundos | root o grupo adm (Debian/Ubuntu); root (RHEL) | logrotate: semanal, 4 generaciones en la configuración por defecto de Debian/Ubuntu y RHEL | grep/zgrep, Plaso, lnav |
| cloud-init Logs and Instance DataInglésDebian · RHEL · SUSE | /var/log/cloud-init.log, /var/log/cloud-init-output.log, /var/lib/cloud/ | How and when a cloud VM was provisioned, which user-data and SSH keys it received, which instance IDs the disk has booted as, and what boot scripts run | Log lines 'YYYY-MM-DD hh:mm:ss,mmm' (UTC in current releases); semaphore and state file times; boot-finished content | root for user-data and sensitive instance data; logs usually root-readable only or adm group | Logs rotated by size where the distro ships a logrotate snippet; /var/lib/cloud persists for the life of the disk; /run/cloud-init is lost at reboot | cloud-init, jq, grep / zgrep, journalctl |
| dmesg, kern.log and the Kernel Ring Buffer on LinuxInglésDebian · RHEL · SUSE · Arch | /dev/kmsg (live ring buffer), /var/log/kern.log (Debian/Ubuntu), /var/log/messages (RHEL, SUSE), journal (-k) | Kernel-level events: crashes and segfaults of exploited processes, OOM kills, device attach, promiscuous interfaces, tainting modules and eBPF warnings | Ring buffer: seconds.microseconds since boot; kern.log/messages: syslog local time; journal: microseconds since epoch, UTC | Ring buffer: root when kernel.dmesg_restrict=1 (Ubuntu default), else any user; log files root or adm group | Ring buffer a few hundred KiB, lost at reboot; kern.log/messages follow logrotate (weekly x 4 by default); journal by size | dmesg, journalctl, grep / zgrep |
| dpkg, APT, RPM and DNF LogsInglésDebian · RHEL | /var/log/dpkg.log, /var/log/apt/history.log, /var/log/dnf.rpm.log | Which packages were installed, upgraded or removed, when, with which command line and by which sudo user | dpkg/APT/DNF logs: host local time; DNF history and RPM install time: Unix epoch seconds (UTC) | dpkg.log and apt/history.log are world-readable; root for complete collection | dpkg and APT: monthly rotation, 12 kept; DNF 4: 1 MB x 4 files; databases until the package is removed | zgrep, sqlite3, rpm --root, dpkg --root, Plaso |
| Journal de systemdDebian · RHEL · SUSE · Arch | /var/log/journal/<machine-id>/ | Lo que registraron los servicios, procesos, usuarios y el kernel, con PID/UID/ejecutable fiables y contexto de arranque | Microsegundos desde la época Unix (UTC) para realtime; microsegundos desde el arranque para monotonic | root (o grupos systemd-journal, adm o wheel); cada usuario puede leer su propio journal user-UID | Por tamaño: 10 % del sistema de archivos con un máximo de 4G por defecto; la copia volátil se pierde al reiniciar | journalctl, Plaso, Velociraptor |
| MySQL, MariaDB and PostgreSQL LogsInglésDebian · RHEL | /var/log/mysql/, /var/log/mariadb/, /var/lib/mysql/ (binlogs), /var/log/postgresql/ (Debian), /var/lib/pgsql/data/log/ (RHEL) | Database logins and failures, statements executed (when logged), data changes in binary logs, and abuse such as file writes or command execution through the database | MySQL 8 error log ISO 8601 UTC by default; MariaDB and PostgreSQL local time unless configured; binlog events in Unix seconds | root or the mysql/postgres service account; client history files owned by each user | Error logs follow logrotate or overwrite schedules; MySQL 8 binlogs expire after 30 days by default; general/query logging is off by default | mysqlbinlog, pgBadger, grep / zgrep, journalctl |