Security Compliance

SEM-Supported Syslog (syslog-ng) Format with Examples

This article provides information about SEM-Supported Syslog (syslog-ng) and Rsyslog.

First published date

4/14/2020 10:39 PM

Last published date

4/22/2025 6:33 PM

Overview

This article provides information about SEM-Supported Syslog (syslog-ng) and Rsyslog.

Product section

Security Event Manager

Cause

N/


 

Resolution

Syslog-NG is the supported syslog format for Security Event Manager. Syslog-NG is the default log forwarding utility for most firewalls, routers, and switches. See RFC 5424: The Syslog Protocol for more information about the Syslog-NG protocol. 

Security Event Manager also accepts syslog data from devices running the Rysylog log forwarding utility. Data logged by Rsyslog-enabled devices must be included in a file with a specific data format so Security Event Manager can read the syslog data. See Will SEM accept Rsyslog and Syslog-ng log data? for more information. 

Older syslog formats sent to Security Event Manager are not supported. See RFC 3164: The BSD syslog Protocol for more information.