Skip to content

Syslog

The standard protocol for sending log messages from devices and systems to a central server.

Why It Matters

Most network devices, Linux systems, and appliances send their logs with syslog. Getting those logs off the device and onto a central server or SIEM is what makes them available, and trustworthy, during an investigation.

Reference

Protocol

Item Details
Standard RFC 5424 (older devices use the BSD format, RFC 3164)
UDP 514 Default; no delivery guarantee
TCP 514 Commonly used for reliable delivery
TCP 6514 Syslog over TLS (RFC 5425)

Message Format

Part Contents
Priority (PRI) Calculated from the facility and the severity
Header Timestamp, hostname, application name, process ID, message ID
Message The event text

Severity Levels

Level Name
0 Emergency
1 Alert
2 Critical
3 Error
4 Warning
5 Notice
6 Informational
7 Debug

How I Use It

On Linux, rsyslog or syslog-ng receives messages and writes them to files under /var/log, or forwards them on to the SIEM. When I set up a new device, I send its logs to the collector and check that they arrive with correct timestamps and hostnames, because a device that has been quietly failing to log is only discovered when its logs are needed.

Resources