Generating Syslog Messages in RFC 5424 Format
Syslog messages that conform to RFC 5424 have an enhanced syslog header. Among other enhancements, the header information better identifies the type of syslog, filters the syslog message, and more precisely defines the syslog generation time, including the year and milliseconds that align to the time zone.
The following table provides a comparison of RFC 3164 and RFC 5424 syslog header information.
Syslog Headers Available for RFC 3164 and RFC 5424
| Syslog RFC 3164 | Syslog RFC 5424 |
|---|---|
| PRIORITY | PRIORITY |
| VERSION | |
| TIMESTAMP | TIMESTAMP |
| HOSTNAME | HOSTNAME |
| APP-NAME | |
| PROCID | |
| MSGID | |
| STRUCTURED-DATA | |
| MSG | MSG |
RFC 5424 provides the following syslog headers:
- PRIORITY: Represents both facility and severity of the messages as described in RFC 3164.
- VERSION: Denotes the version of the syslog protocol specification.
- TIMESTAMP: Provides a formalized timestamp that
denotes the date and time when the event is logged and includes the syslog
generation time with the year and milliseconds that align to the time zone.
The following example shows the date and time format defined in RFC 5424.
2020-08-13T22:14:15.003Z represents August 13, 2020 at 10:14 PM and 15 seconds, 3 milliseconds into the next second. The timestamp is in UTC. The timestamp provides millisecond resolution.
Note: The suffix "Z", when applied to a time, denotes a Coordinated Universal Time (UTC) offset of 00:00. - HOSTNAME: Identifies the machine that originally
sent the syslog message. The contents of the HOSTNAME field may have one of the
following values and uses the following order of preference:
Note: When both the fully qualified domain name (FQDN) and the hostname are configured for inclusion in logging, the format hostname.fqdn (for example "host1.ruckuswireless.com") is displayed.
- APP-NAME: Identifies the device or application from which the message originated. The APP-NAME is intended for filtering messages on a relay or collector. The NILVALUE is used when the syslog application is incapable of obtaining its APP-NAME.
- PROCID: Often used to provide the process name or process ID associated with a syslog system. The NILVALUE is used when a process ID is not available.
- MSGID: Identifies the type of message. The NILVALUE is used when the syslog application does not, or cannot, provide any value.
- STRUCTURED-DATA: Provides a mechanism to express information in a well-defined, easy-to-interpret data format. STRUCTURED-DATA can contain zero, one, or multiple structured-data elements. If there is no structured-data element, the STRUCTURED-DATA field uses NILVALUE.
- MSG: Contains a free-form message that provides information about the event.