Skip to content

Linux Log Parser

auth.log, syslog, secure, the systemd journal, auditd and wtmp/btmp in one timeline: SSH logins and brute force, sudo and su, new accounts, cron and systemd persistence, rebuilt sessions and signs of log tampering. Parsed in your browser with WebAssembly; your logs are never uploaded.

Drop Linux logs, a /var/log folder or a UAC / Velociraptor collection

auth.log, secure, syslog, messages (rotated and .gz), *.journal, journalctl -o export / -o json, audit.log, wtmp, btmp, utmp, lastlog, wtmp.db, lastlog2.db, plus /etc/localtime, /etc/timezone and /etc/passwd for context. Files, folders, .zip, .tar and .tar.gz.

The sample is synthetic: a fictional intrusion on the jump host fin-jump-01, safe to explore.

Parsed in your browser. Nothing is uploaded.

How to get your logs

Full collection guide

The parser reads the files as they are on the host: text logs (rotated and compressed too), journal files, audit.log and the binary login records. Copy them with root rights, keep the folder layout, and drop the archive here.

  1. Collect as root (one command)
  2. Drop the .tar.gz or folder here
  3. Parsed locally, never uploaded

On the host, as root: one archive with /var/log (text logs, journal, audit, wtmp/btmp/lastlog), the volatile journal and the context files. Missing paths are skipped with a warning.

bash · root
sudo tar -C / -czf /tmp/linux-logs.tar.gz --ignore-failed-read --sparse \
  var/log run/log/journal etc/localtime etc/timezone etc/passwd etc/hostname

Copy /tmp/linux-logs.tar.gz to your workstation and drop it here as it is: the archive is opened in the browser.

bash
scp user@host:/tmp/linux-logs.tar.gz .

If you can only run journalctl

journalctl's export format is lossless and keeps every field; this tool reads it as well as -o json. Raw journal files are still better: they keep sequence numbers, which reveal deleted entries.

bash · root
sudo journalctl -o export > journal.export
sudo journalctl -D /mnt/evidence/var/log/journal -o export > journal.export   # from a mounted image

All rotated audit logs in one file, in raw format:

bash · root
sudo ausearch --input-logs --raw > audit.log

Before you collect

  • Run as root: auth.log, btmp, audit.log and the journal are not readable by ordinary users.
  • Take every rotation (.1, .2.gz, dated files) and the .journal~ files: they hold the older history and damaged tails.
  • Copy /run/log/journal on a live host: a volatile journal is lost at reboot.
  • lastlog is a sparse file that can look huge; tar --sparse (as above) stores only the used slots.
  • Keep a hash of the archive and note when you collected: logrotate may run while you work.

What Linux Log Parser reads

A Linux host records authentication, privilege use and service activity in several places at once: text files written by rsyslog (auth.log and syslog on Debian and Ubuntu, secure and messages on RHEL), the binary systemd journal, the audit log written by auditd, and the binary login records wtmp, btmp, utmp and lastlog (or wtmpdb and lastlog2 on newer systems).

This tool reads all of them in your browser and puts them in one timeline. Each line is normalized into an event with its host, program, process id, user, source address and command, and classified: SSH logins and failures, sudo and su, account and password changes, cron and systemd changes, kernel modules, logging being stopped. Logins and logouts are paired into sessions, with the commands run inside them when auditd recorded them.

Where the files are

  • /var/log/auth.log, /var/log/syslog (Debian, Ubuntu) and /var/log/secure, /var/log/messages (RHEL, Rocky, Alma, Fedora), with their rotations (.1, .2.gz, dated names).
  • /var/log/journal/<machine-id>/*.journal and *.journal~ (persistent journal), /run/log/journal/ (volatile).
  • /var/log/audit/audit.log and its rotations (audit.log.1 …).
  • /var/log/wtmp, /var/log/btmp, /var/log/lastlog, /run/utmp; wtmpdb at /var/lib/wtmpdb/wtmp.db (Debian 13: /var/log/wtmp.db) and lastlog2 at /var/lib/lastlog/lastlog2.db.
  • /etc/localtime or /etc/timezone (time zone for traditional syslog lines) and /etc/passwd (UID to name).

What it shows

  • Password guessing followed by a successful login, from the same or another address; logins from addresses an account never used; direct root logins.
  • sudo and su use, including interactive root shells, and failed or refused attempts.
  • Accounts created, added to admin groups or given a new password; crontab edits, systemd unit files and units that start for the first time; kernel modules.
  • Signs of log tampering: gaps in journal sequence numbers, auth lines present in the journal but missing from auth.log, blanked or truncated wtmp records, stopped logging services and log-clearing commands.
  • Sessions from login to logout, rebuilt from sshd and PAM lines, systemd-logind, audit session ids and wtmp, with what happened inside them.

What it cannot tell you

  • Logs only contain what was logged: without execve audit rules there is no record of commands, and shell builtins are never recorded.
  • Messages are written by programs, and any local user can inject look-alike lines with logger. The journal's underscore fields (_UID, _EXE, _CMDLINE) are the trusted ones.
  • Traditional syslog lines have no year and no zone: the result depends on the file's date and the zone you set. The tool says when it guessed.
  • Findings are leads, not verdicts: administrators produce many of the same traces. Web server logs are not parsed.

How to get the files

  • Easiest: as root, tar /var/log, /run/log/journal and /etc/localtime, /etc/timezone, /etc/passwd, /etc/hostname into one .tar.gz and drop it here (see the guide above).
  • UAC collections (tar.gz) and Velociraptor ZIPs can be dropped as they are.
  • On a dead box, mount the file system read-only and archive the same paths.

Questions

Are my logs uploaded?

No. The files are read and parsed in your browser by WebAssembly running in a Web Worker. Nothing is sent to a server; closing the tab forgets everything.

Can it read binary journal files without journalctl?

Yes. The engine decodes the journal file format directly, including the compact layout of systemd 252 and later and fields compressed with XZ, LZ4 or ZSTD. It also reads journalctl -o export and -o json output.

How does it handle auth.log lines without a year?

Traditional syslog lines (Sep 14 10:02:11) have no year and no time zone. The tool counts years back from the file's modification time (or the newest dated event) and converts local time with the zone from /etc/localtime or /etc/timezone. Both can be set by hand, and every guessed time is marked.

Why do some auth.log lines show as duplicates?

On systemd hosts rsyslog receives its lines from journald, so auth.log and the journal hold the same events. The journal copy has trusted fields and microsecond times, so the text line is marked as a duplicate and hidden by default. Lines present in only one of them are kept and, for auth lines missing from auth.log, reported.

Does it detect deleted log entries?

It reports what can be measured: gaps in journal sequence numbers, auth entries the journal holds but auth.log does not, blanked or truncated wtmp records, and commands that stop logging or delete logs. A clean result does not prove nothing was removed.

Which distributions are supported?

Debian, Ubuntu, RHEL and its rebuilds, Fedora, SUSE and Arch layouts: rsyslog traditional and RFC 3339 formats, RFC 5424, the systemd journal, auditd RAW and ENRICHED logs, wtmp in both the x86_64 and aarch64 record layouts, wtmpdb and lastlog2.

Reconstruct command lines from Linux audit.log: grouping records by event, EXECVE argument reassembly, hex-encoded arguments, auid and ses across sudo.
Read /var/log/auth.log and /var/log/secure in an investigation: SSH brute force and logins, sudo and su root shells, password and account changes, time formats.
What to collect for a Linux log investigation and how: one tar command on a live host, journalctl export, ausearch, UAC, Velociraptor, or a mounted disk image.