Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
logs introduction linux log inspection log forensics technology system standard technical framework linux environment standard log type event viewer log implementation suggestions open full-room system major off-site emergency facilities various axial flow cooling fans
GA/T 1663-2019 in English

GA/T 1663-2019 in English

VALID

Forensic sciences -- Technical specifications for examination of Linux operating system logs

  • Issued on:2019-10-14
  • Implemented on:2019-12-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $110.00
$107.00

本标准规定了Linux操作系统日志检验的方法。
本标准适用于法庭科学领域中的电子物证检验。


Introduction

Linux log inspection standard technical framework

As a supplementary specification to GA/T 1071-2013, this standard systematically establishes a log forensics technology system in the Linux environment for the first time. The core innovations include:

Dimension Windows standard (GA/T 1071) Linux standard
Log type Event viewer log as the main one syslog system + binary log
Time zone processing Automatic conversion Manual calibration of time zone offset is required
Configuration file Registry storage /etc/rsyslog.conf and other text configuration

Detailed explanation of key inspection process

Typical operation case

In a server intrusion case, the log file analyzed by the electronic evidence inspection workstation showed:

  1. Use the journalctl -u sshd command to extract SSH login exception records
  2. Found traces of brute force cracking in /var/log/secure
  3. Through timestamp conversion, it was determined that the attack occurred at 2:15 am in the UTC+8 time zone

Technology evolution analysis

Compared with the 2013 version of the Windows standard, this specification has the following major breakthroughs:

  • Added parsing requirements for binary logs (such as systemd journal)
  • Cleared the inspection method for the log rotation mechanism (logrotate)
  • Specified the standardized process for time zone conversion

Implementation Recommendations

Hardware Configuration: It is recommended that the forensic workstation be equipped with a read-only interface and at least 2TB of dedicated storage media

Software Tools: Must include:

1logrotate analysis module
2journalctl compatible tool
3Time zone conversion calculator

Sample only — not a preview of GA/T 1663-2019
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend

  • GA/T 2137-2024 in English

    GA/T 2137-2024 in English

    Forensic Science: Detection of Δ9-tetrahydrocannabinol and other four components in industrial hemp and its processed products by liquid chromatography and liquid chromatography-mass spectrometry

    2024-04-17