Perform forensic investigation of Linux system logs including syslog, auth.log, systemd journal (via journalctl), kern.log, auditd, and application logs to reconstruct user sessions, identify unauthorized access and privilege escalation, trace lateral movement, and establish event timelines. Use when investigating a suspected compromise of a Linux system and needing to analyze SSH, sudo, cron, or kernel-level activity from plain-text or systemd journal logs.