Syslog
Definition
A standardised protocol (RFC 5424) for transmitting log messages from network devices to a centralised log server. Routers, switches, firewalls, and servers all generate syslog entries. The evidentiary value depends on the accuracy of the generating device's clock and the integrity of the log server.
- Standard
- RFC 5424
- Generators
- Routers, switches, firewalls, servers
- Purpose
- Transmit log messages to a centralised log server
- Evidentiary dependency
- Generating device clock accuracy and log server integrity
Common questions
Why is a device's clock accuracy specifically flagged as a limitation for syslog evidence?+
Syslog timestamps are generated locally by each device, so if a router or firewall's clock has drifted or was never synchronised via NTP, its log entries can be minutes or hours off from actual event time, which undermines timeline correlation with other evidence unless the drift is identified and corrected.
How does an examiner establish that syslog entries have not been altered after collection?+
By verifying chain of custody for the log export, checking for gaps in sequential message identifiers or timestamps, comparing entries against independent sources such as NetFlow or a second log destination, and confirming the log server itself was not compromised during the relevant period.
Why is centralised syslog collection considered more forensically valuable than reading logs directly off each device?+
A compromised device's local logs can be altered or deleted by an attacker with sufficient access, but a centralised server receiving forwarded syslog messages preserves an independent copy that is harder to tamper with retroactively, provided the server itself is properly secured.
Related terms
- DHCP Lease Log
- A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
- Intrusion Detection System (IDS)
- A network or host-based monitoring system that analyses traffic or system behaviour against a rule set (signature-based) or a statistical baseline (anomaly-based)...
- NetFlow
- A network protocol (originally Cisco, now standardised as IPFIX under RFC 7011) that records metadata about IP traffic flows: source and destination...
- PCAP (Packet Capture)
- A file format (and the process of creating it) that records every byte of every network packet passing a capture point, including...
- RADIUS Log
- An authentication, authorisation, and accounting record produced by a Remote Authentication Dial-In User Service server. Each entry records the username, authenticating device...