IT Forensics · Linux

Forensic analysis of rsyslog configuration – correctly assessing the scope of logging

rsyslog is one of the most widely used implementations of the Syslog standard on Linux and offers extensive configuration options for filtering, forwarding and storing log data.

Enquire without obligation

The specific rsyslog configuration determines which events are logged in the first place, where they are forwarded to, and how long they are retained. This configuration must be analysed before the log content is examined, in order to correctly assess the significance of the logs.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We analyse the active rsyslog configuration to determine the actual scope of logging, any forwarding to the central Log-Server system, and the configured retention period.

Typical areas of application

Assessment of the actual scope of logging
Tracking log forwards to central systems
Investigation into logging configurations that have been altered retrospectively
Preparing for a proper Syslog analysis
Incident Response on Linux Systems
Judicial and non-judicial expert reports

This is how the rsyslog configuration is organised

Once the backup has been completed, the existing rsyslog configuration is systematically analysed, including active filter rules, destination systems and rotation settings. The configuration is then checked for any signs of subsequent changes before the actual log analysis takes place.

Why is this classification relevant from a forensic perspective?

Without knowledge of the active configuration, it is not possible to reliably assess whether the absence of certain protocol entries is due to the events not actually having taken place, or to deliberate or inadequate configuration.

If there is any suspicion that the logging configuration has been altered retrospectively, for example to conceal activities, this will be investigated and documented separately.

Frequently Asked Questions

Can an rsyslog configuration be tampered with to conceal traces?+
Yes, specifically adjusting the filter rules may result in certain events no longer being logged. This is taken into account during classification.
Are logs frequently forwarded to the central Server?+
Centralised log collection is common in enterprise environments, which can open up additional, independent sources of analysis.
Does the configuration analysis replace the actual log analysis?+
No, it is a necessary preparatory step that helps to contextualise the subsequent analysis of the content correctly.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into the „forensic analysis of rsyslog configuration"? LanCologne can assist you with the court-admissible preservation of digital evidence and the transparent analysis of relevant Linux artefacts.

Get in touch now