IT Forensics · Linux
Forensic analysis of rsyslog configuration – correctly assessing the scope of logging
rsyslog is one of the most widely used implementations of the Syslog standard on Linux and offers extensive configuration options for filtering, forwarding and storing log data.
The specific rsyslog configuration determines which events are logged in the first place, where they are forwarded to, and how long they are retained. This configuration must be analysed before the log content is examined, in order to correctly assess the significance of the logs.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We analyse the active rsyslog configuration to determine the actual scope of logging, any forwarding to the central Log-Server system, and the configured retention period.
Typical areas of application
This is how the rsyslog configuration is organised
Once the backup has been completed, the existing rsyslog configuration is systematically analysed, including active filter rules, destination systems and rotation settings. The configuration is then checked for any signs of subsequent changes before the actual log analysis takes place.
Why is this classification relevant from a forensic perspective?
Without knowledge of the active configuration, it is not possible to reliably assess whether the absence of certain protocol entries is due to the events not actually having taken place, or to deliberate or inadequate configuration.
If there is any suspicion that the logging configuration has been altered retrospectively, for example to conceal activities, this will be investigated and documented separately.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into the „forensic analysis of rsyslog configuration"? LanCologne can assist you with the court-admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.
Related to this topic
- Systematically analysing the /var/log directory from a forensic perspective – comprehensively capturing the central log collection
- Forensic analysis of the kernel ring buffer (dmesg) – Reconstructing early system events
- Forensic analysis of load and load log records – Evaluating login histories in a traceable manner
- Forensic analysis of wtmp and utmp files – analysing session data in detail