Network Management

Syslog facilities

This article provides information on Syslog facilities.

First published date

10/12/2018 1:37 PM

Last published date

5/24/2021 7:59 AM

Overview

This article provides information on Syslog facilities. 

The facility value is used to determine which process of the machine created the message. Since the Syslog protocol was originally written on BSD Unix, the Facilities reflect the names of UNIX processes and daemons. The following tables list Syslog facilities and levels.

Product section

Network Performance Monitor

Resolution

Number

Source

Number

Source

0

kernel messages

12

NTP subsystem

1

user-level messages

13

log audit

2

mail system

14

log  alert

3

system daemons

15

clock daemon

4

security/authorization messages

16

local use 0 (local0)

5

messages generated internally by Syslog

17

local use 1 (local1)

6

line printer subsytem

18

local use 2 (local2)

7

network news subsytem

19

local use 2 (local3)

8

UUCP subsystem

20

local use 2 (local4)

9

clock daemon

21

local use 2 (local5)

10

security/authorization messages

22

local use 2 (local6)

11

FTP daemon

23

local use 2 (local7)

Note: If you are receiving messages from a UNIX system, consider using the User Facility as your first choice. Local0 through Local7 are not used by UNIX and are traditionally used by networking equipment. Cisco routers, for example, use Local6 or Local7.

 

Syslog RFC 3164 header format

The HEADER part contains a timestamp and an indication of the hostname or IP address of the device. The HEADER contains two fields called the TIMESTAMP and the HOSTNAME.

The TIMESTAMP will immediately follow the trailing ">" from the PRI part and single space characters MUST follow each of the TIMESTAMP and HOSTNAME fields.

HOSTNAME will contain the hostname, as it knows itself. If it does not have a hostname, then it will contain its own IP address.

The TIMESTAMP field is the local time and is in the format of: "Mmm dd hh:mm:ss" (without the quote marks).

The MSG part has two fields known as the TAG field and the CONTENT field. The value in the TAG field will be the name of the program or process that generated the message. The CONTENT contains the details of the message. This has traditionally been a freeform message that gives some detailed information of the event. The TAG is a string of ABNF alphanumeric characters that MUST NOT exceed 32 characters. Any non-alphanumeric character will terminate the TAG field and will be assumed to be the starting character of the CONTENT field. Most commonly, the first character of the CONTENT field that signifies the conclusion of the TAG field has been seen to be the left square bracket character ("["), a colon character (":"), or a space character

Kiwi SyslogGen uses the following format for its messages:

<PRI>Jul 10 12:00:00 192.168.1.1 SyslogGen MESSAGE TEXT

The BSD Syslog protocol is discussed in RFC 3164. Check out their community discussion on Roxen website.

For a comprehensive description of the syslog protocol, see Sans Institute website.