Generating the Syslog Specific to RFC 5424

By default, syslog is generated in accordance with RFC 3164. To provide the maximum amount of information in every syslog in a structured format, you can enable syslog logging specific to RFC 5424.

The syslog that conforms to RFC 5424 has an enhanced syslog header that helps to identify the type of syslog, filter the syslog message, identify the syslog generation time with the year and milliseconds with respect to the time zone, and other enhancements. The syslog specific to RFC 5424 can be enabled using the logging enable rfc5424 command. The logging buffer must be cleared before enabling syslog specific to RFC 5424; otherwise, the system displays an error.

Note: If the logging cli-command command is present in the running configuration, switching between syslog functionality that follows the default RFC 3164 standard and syslog specific to RFC 5424 standard is not supported.

The following table provides a comparison of the syslog header information available in the RFC 3164 and RFC 5424 syslog logging.

Syslog Headers Available for RFC 3164 and RFC 5424

Syslog RFC 3164 Syslog RFC 5424
PRIORITY PRIORITY
  VERSION
TIMESTAMP TIMESTAMP
HOSTNAME HOSTNAME
  APP-NAME
  PROCID
  MSGID
  STRUCTURED-DATA
MSG MSG

RFC 5424 provides the following syslog headers:

  • PRIORITY: Represents both facility and severity of the messages as described in RFC 3164.
  • VERSION: Denotes the version of the syslog protocol specification.
  • TIMESTAMP: A formalized timestamp that denotes the date and time when the event is logged and includes the syslog generation time with the year and milliseconds with respect to the time zone.

    The following example shows the date and time format in RFC 5424.

    2020-08-13T22:14:15.003Z represents August 13, 2020 at 10:14 PM and 15 seconds, 3 milliseconds into the next second. The timestamp is in UTC. The timestamp provides millisecond resolution.

    Note: The suffix "Z", when applied to a time, denotes a Coordinated Universal Time (UTC) offset of 00:00.

  • HOSTNAME: Identifies the machine that originally sent the syslog message. The contents of the HOSTNAME field may have one of the following values and the field uses the following order of preference:
    • FQDN
    • Hostname
    • NILVALUE: A field used when the syslog application is incapable of obtaining its host name.
  • APP-NAME: Identifies the device or application from which the message is originated. The APP-NAME is intended for filtering messages on a relay or collector. The NILVALUE is used when the syslog application is incapable of obtaining its APP-NAME.
  • PROCID: Often used to provide the process name or process ID associated with a syslog system. The NILVALUE is used when a process ID is not available.
  • MSGID: Identifies the type of message. The NILVALUE is used when the syslog application does not, or cannot, provide any value.
  • STRUCTURED-DATA: Provides a mechanism to express information in a well-defined and interpretable data format as per RFC 5424. STRUCTURED-DATA can contain zero, one, or multiple structured-data elements. In case of zero structured-data elements, the STRUCTURED-DATA field uses NILVALUE.
  • MSG: Contains a free-form message that provides information about the event.