IT Forensics · Linux

Forensic analysis of syslog artefacts – analysing traditional text logs

Syslog is the traditional, text-based logging standard under Linux and Unix, and continues to be used on many systems alongside or instead of journald. Messages are categorised according to priority and source facility.

Enquire without obligation

Syslog files are usually subject to log rotation, whereby older entries are compressed, archived or deleted. For a comprehensive forensic analysis, therefore, rotated and archived log files must also be taken into account.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We back up and analyse all available syslog files, including rotated and compressed archives, and use them to reconstruct a chronological sequence of events that is as complete as possible.

Typical areas of application

Reconstruction of historical system events
Investigation of services without journald support
Analysis of archived and rotated log files
Correlation with other log sources
Incident Response on Linux Systems
Judicial and non-judicial expert reports

How a Syslog analysis works

Following the backup, all current, rotated and archived syslog files are identified and collated in chronological order. Any notable gaps in the rotation are documented separately. The results are cross-checked against other log sources such as journald or auditd.

Why is syslog analysis relevant in a forensic context?

On many systems, Syslog contains log data that is not present in journald, or is only partially present, such as data from older services or specially configured applications.

As log rotation systematically removes or archives older entries, a timely backup is crucial for ensuring the most complete reconstruction possible.

Frequently Asked Questions

Is Syslog still used on modern systems?+
Yes, often in parallel with `journald`, particularly for certain services or where the system is configured accordingly.
What happens during log rotation?+
Older log files are compressed, archived and deleted after a configured retention period.
Can rotated log files still be analysed?+
Yes, provided they are still present on the system or in backups, they can be included in the forensic analysis.

LanCologne – Linux Forensics Cologne

Do you require a professional forensic investigation into „the forensic analysis of syslog artefacts"? LanCologne can assist you in the legally admissible preservation of digital evidence and the traceable analysis of relevant Linux artefacts.

Get in touch now