Enabling RFC 5424 for Enhanced Syslog Messages
With RFC 5424 enabled, syslog messages include details such as a more detailed timestamp, structured data, the hostname (potentially including the domain name), and the syslog sequence ID.
The following message shows a syslog message formatted according to the default RFC 3164 standards..
Oct 11 04:33:04:I:Security: Security: user test added by cli from CONSOLE session. by cli user from console session
The following message shows the same syslog message when RFC 5424 is enabled.
2023-10-10T20:41:05Z:I: george ICX7650_Router - Security [meta sequenceId=1] BOM Security: Security: user test modified by cli from CONSOLE session. by cli user from console session
Refer to Generating Syslog Messages in RFC 5424 Format for more specific information on message contents.
Perform the following steps to enable enhanced syslog messages that follow RFC 5424 format.
- Enter global configuration mode.
- Enable RFC 5424 logging.
- (Optional) If not already configured, configure the hostname for the ICX device.
- (Optional) Enter the
ip dns domain-listcommand followed by the fully qualified domain name (FQDN) of the ICX device to include the FQDN in syslog messages.
The following example produces the hostname and
domain name combination
ruckuswireless.com device in RFC 5424-format syslog messages.
device# configure terminal device(config)# hostname device device(config)# logging enable rfc5424 device(config)# ip dns domain-list ruckuswireless.com