Generating Syslog Messages in RFC 5424 Format

By default, syslog messages are generated in accordance with RFC 3164. To provide the maximum amount of information in every syslog message in a structured format, you can enable syslog logging that conforms to RFC 5424.

Syslog messages that conform to RFC 5424 have an enhanced syslog header. Among other enhancements, the header information better identifies the type of syslog, filters the syslog message, and more precisely defines the syslog generation time, including the year and milliseconds that align to the time zone.

The following table provides a comparison of RFC 3164 and RFC 5424 syslog header information.

Syslog Headers Available for RFC 3164 and RFC 5424

Syslog RFC 3164 Syslog RFC 5424
PRIORITY PRIORITY
  VERSION
TIMESTAMP TIMESTAMP
HOSTNAME HOSTNAME
  APP-NAME
  PROCID
  MSGID
  STRUCTURED-DATA
MSG MSG

RFC 5424 provides the following syslog headers:

  • PRIORITY: Represents both facility and severity of the messages as described in RFC 3164.
  • VERSION: Denotes the version of the syslog protocol specification.
  • TIMESTAMP: Provides a formalized timestamp that denotes the date and time when the event is logged and includes the syslog generation time with the year and milliseconds that align to the time zone.

    The following example shows the date and time format defined in RFC 5424.

    2020-08-13T22:14:15.003Z represents August 13, 2020 at 10:14 PM and 15 seconds, 
    3 milliseconds into the next second. The timestamp is in UTC. 
    The timestamp provides millisecond resolution. 
    Note: The suffix "Z", when applied to a time, denotes a Coordinated Universal Time (UTC) offset of 00:00.

  • HOSTNAME: Identifies the machine that originally sent the syslog message. The contents of the HOSTNAME field may have one of the following values and uses the following order of preference:
    Note: When both the fully qualified domain name (FQDN) and the hostname are configured for inclusion in logging, the format hostname.fqdn (for example "host1.ruckuswireless.com") is displayed.
    • FQDN
    • Hostname
    • NILVALUE: A hyphen (-) symbol used when the syslog application is incapable of obtaining its host name.
  • APP-NAME: Identifies the device or application from which the message originated. The APP-NAME is intended for filtering messages on a relay or collector. The NILVALUE is used when the syslog application is incapable of obtaining its APP-NAME.
  • PROCID: Often used to provide the process name or process ID associated with a syslog system. The NILVALUE is used when a process ID is not available.
  • MSGID: Identifies the type of message. The NILVALUE is used when the syslog application does not, or cannot, provide any value.
  • STRUCTURED-DATA: Provides a mechanism to express information in a well-defined, easy-to-interpret data format. STRUCTURED-DATA can contain zero, one, or multiple structured-data elements. If there is no structured-data element, the STRUCTURED-DATA field uses NILVALUE.
  • MSG: Contains a free-form message that provides information about the event.