Network Management
Syslog facilities
This article provides information on Syslog facilities.
First published date
Last published date
Overview
This article provides information on Syslog facilities.
The facility value is used to determine which process of the machine created the message. Since the Syslog protocol was originally written on BSD Unix, the Facilities reflect the names of UNIX processes and daemons. The following tables list Syslog facilities and levels.
Product section
Resolution
|
Number |
Source |
Number |
Source |
|
0 |
kernel messages |
12 |
NTP subsystem |
|
1 |
user-level messages |
13 |
log audit |
|
2 |
mail system |
14 |
log alert |
|
3 |
system daemons |
15 |
clock daemon |
|
4 |
security/authorization messages |
16 |
local use 0 (local0) |
|
5 |
messages generated internally by Syslog |
17 |
local use 1 (local1) |
|
6 |
line printer subsytem |
18 |
local use 2 (local2) |
|
7 |
network news subsytem |
19 |
local use 2 (local3) |
|
8 |
UUCP subsystem |
20 |
local use 2 (local4) |
|
9 |
clock daemon |
21 |
local use 2 (local5) |
|
10 |
security/authorization messages |
22 |
local use 2 (local6) |
|
11 |
FTP daemon |
23 |
local use 2 (local7) |
Note: If you are receiving messages from a UNIX system, consider using the User Facility as your first choice. Local0 through Local7 are not used by UNIX and are traditionally used by networking equipment. Cisco routers, for example, use Local6 or Local7.
Syslog RFC 3164 header format
The HEADER part contains a timestamp and an indication of the hostname or IP address of the device. The HEADER contains two fields called the TIMESTAMP and the HOSTNAME.
The TIMESTAMP will immediately follow the trailing ">" from the PRI part and single space characters MUST follow each of the TIMESTAMP and HOSTNAME fields.
HOSTNAME will contain the hostname, as it knows itself. If it does not have a hostname, then it will contain its own IP address.
The TIMESTAMP field is the local time and is in the format of: "Mmm dd hh:mm:ss" (without the quote marks).
The MSG part has two fields known as the TAG field and the CONTENT field. The value in the TAG field will be the name of the program or process that generated the message. The CONTENT contains the details of the message. This has traditionally been a freeform message that gives some detailed information of the event. The TAG is a string of ABNF alphanumeric characters that MUST NOT exceed 32 characters. Any non-alphanumeric character will terminate the TAG field and will be assumed to be the starting character of the CONTENT field. Most commonly, the first character of the CONTENT field that signifies the conclusion of the TAG field has been seen to be the left square bracket character ("["), a colon character (":"), or a space character
Kiwi SyslogGen uses the following format for its messages:
<PRI>Jul 10 12:00:00 192.168.1.1 SyslogGen MESSAGE TEXT
The BSD Syslog protocol is discussed in RFC 3164. Check out their community discussion on Roxen website.
For a comprehensive description of the syslog protocol, see Sans Institute website.