Skip to content

Syslog

Definition

A standardised protocol (RFC 5424) for transmitting log messages from network devices to a centralised log server. Routers, switches, firewalls, and servers all generate syslog entries. The evidentiary value depends on the accuracy of the generating device's clock and the integrity of the log server.

Standard
RFC 5424
Generators
Routers, switches, firewalls, servers
Purpose
Transmit log messages to a centralised log server
Evidentiary dependency
Generating device clock accuracy and log server integrity

Common questions

Why is a device's clock accuracy specifically flagged as a limitation for syslog evidence?+

Syslog timestamps are generated locally by each device, so if a router or firewall's clock has drifted or was never synchronised via NTP, its log entries can be minutes or hours off from actual event time, which undermines timeline correlation with other evidence unless the drift is identified and corrected.

How does an examiner establish that syslog entries have not been altered after collection?+

By verifying chain of custody for the log export, checking for gaps in sequential message identifiers or timestamps, comparing entries against independent sources such as NetFlow or a second log destination, and confirming the log server itself was not compromised during the relevant period.

Why is centralised syslog collection considered more forensically valuable than reading logs directly off each device?+

A compromised device's local logs can be altered or deleted by an attacker with sufficient access, but a centralised server receiving forwarded syslog messages preserves an independent copy that is harder to tamper with retroactively, provided the server itself is properly secured.

Related terms

DHCP Lease Log
A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
Intrusion Detection System (IDS)
A network or host-based monitoring system that analyses traffic or system behaviour against a rule set (signature-based) or a statistical baseline (anomaly-based)...
NetFlow
A network protocol (originally Cisco, now standardised as IPFIX under RFC 7011) that records metadata about IP traffic flows: source and destination...
PCAP (Packet Capture)
A file format (and the process of creating it) that records every byte of every network packet passing a capture point, including...
RADIUS Log
An authentication, authorisation, and accounting record produced by a Remote Authentication Dial-In User Service server. Each entry records the username, authenticating device...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.