Generating the Syslog Specific to RFC 5424
The syslog that conforms to RFC 5424 has an
enhanced syslog header that helps to identify the type of syslog, filter the syslog
message, identify the syslog generation time with the year and milliseconds with
respect
to the time zone, and other enhancements. The syslog specific to RFC 5424 can be
enabled
using the logging enable
rfc5424 command. The logging buffer must be cleared before enabling syslog
specific to RFC 5424; otherwise, the system displays an error.
logging cli-command
command is present in the running configuration, switching between syslog
functionality that follows the default RFC 3164 standard and syslog specific to
RFC
5424 standard is not supported. The following table provides a comparison of the syslog header information available in the RFC 3164 and RFC 5424 syslog logging.
Syslog Headers Available for RFC 3164 and RFC 5424
| Syslog RFC 3164 | Syslog RFC 5424 |
|---|---|
| PRIORITY | PRIORITY |
| VERSION | |
| TIMESTAMP | TIMESTAMP |
| HOSTNAME | HOSTNAME |
| APP-NAME | |
| PROCID | |
| MSGID | |
| STRUCTURED-DATA | |
| MSG | MSG |
RFC 5424 provides the following syslog headers:
- PRIORITY: Represents both facility and severity of the messages as described in RFC 3164.
- VERSION: Denotes the version of the syslog protocol specification.
- TIMESTAMP: A formalized timestamp that denotes the
date and time when the event is logged and includes the syslog generation time
with the year and milliseconds with respect to the time zone.
The following example shows the date and time format in RFC 5424.
2020-08-13T22:14:15.003Z represents August 13, 2020 at 10:14 PM and 15 seconds, 3 milliseconds into the next second. The timestamp is in UTC. The timestamp provides millisecond resolution.
Note: The suffix "Z", when applied to a time, denotes a Coordinated Universal Time (UTC) offset of 00:00. - HOSTNAME: Identifies the machine that originally sent the syslog message. The contents of the HOSTNAME field may have one of the following values and the field uses the following order of preference:
- APP-NAME: Identifies the device or application from which the message is originated. The APP-NAME is intended for filtering messages on a relay or collector. The NILVALUE is used when the syslog application is incapable of obtaining its APP-NAME.
- PROCID: Often used to provide the process name or process ID associated with a syslog system. The NILVALUE is used when a process ID is not available.
- MSGID: Identifies the type of message. The NILVALUE is used when the syslog application does not, or cannot, provide any value.
- STRUCTURED-DATA: Provides a mechanism to express information in a well-defined and interpretable data format as per RFC 5424. STRUCTURED-DATA can contain zero, one, or multiple structured-data elements. In case of zero structured-data elements, the STRUCTURED-DATA field uses NILVALUE.
- MSG: Contains a free-form message that provides information about the event.