IT Forensics · Linux
Forensic analysis of syslog artefacts – analysing traditional text logs
Syslog is the traditional, text-based logging standard under Linux and Unix, and continues to be used on many systems alongside or instead of journald. Messages are categorised according to priority and source facility.
Syslog files are usually subject to log rotation, whereby older entries are compressed, archived or deleted. For a comprehensive forensic analysis, therefore, rotated and archived log files must also be taken into account.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.
Our services
We back up and analyse all available syslog files, including rotated and compressed archives, and use them to reconstruct a chronological sequence of events that is as complete as possible.
Typical areas of application
How a Syslog analysis works
Following the backup, all current, rotated and archived syslog files are identified and collated in chronological order. Any notable gaps in the rotation are documented separately. The results are cross-checked against other log sources such as journald or auditd.
Why is syslog analysis relevant in a forensic context?
On many systems, Syslog contains log data that is not present in journald, or is only partially present, such as data from older services or specially configured applications.
As log rotation systematically removes or archives older entries, a timely backup is crucial for ensuring the most complete reconstruction possible.
Frequently Asked Questions
LanCologne – Linux Forensics Cologne
Do you require a professional forensic investigation into „the forensic analysis of syslog artefacts"? LanCologne can assist you in the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.
Related to this topic
- Forensic analysis of rsyslog configuration – correctly assessing the scope of logging
- Systematically analysing the /var/log directory from a forensic perspective – comprehensively capturing the central log collection
- Forensic analysis of the kernel ring buffer (dmesg) – Reconstructing early system events
- Forensic analysis of load and load log records – Evaluating login histories in a traceable manner