Skip to content

Syslog (RFC 5424)

Definition

A standard protocol and message format for transmitting log data from Unix-like systems and network devices to a centralised collector. Each message carries a facility code, severity level, timestamp, hostname, and message text. The primary transport mechanism for centralised log aggregation.

Standard
RFC 5424
Message fields
Facility code, severity level, timestamp, hostname, message text
Role
Primary transport for centralised log aggregation
Source systems
Unix-like systems and network devices

Common questions

What does the facility code in a syslog message tell an analyst?+

The facility code identifies the general source subsystem that generated the message, such as kernel, mail, authentication, or a locally-defined application facility, which lets an analyst filter a large aggregated log stream down to the subsystem relevant to the incident being investigated.

How does severity level filtering affect what evidence survives in a server log analysis?+

If a system or log server is configured to forward or retain only messages above a certain severity threshold, lower-severity informational or debug messages that could carry investigative detail may never reach the central collector, so an examiner needs to know the configured filtering before concluding evidence is genuinely absent.

Why does RFC 5424 matter specifically, given syslog has existed since the 1980s?+

RFC 5424 standardised a structured message format including a defined timestamp format and structured data fields, replacing the looser, inconsistent formats of the earlier de facto BSD syslog protocol, which improves cross-device log parsing consistency in an analysis pipeline.

Related terms

Binary Log (Database)
A database engine's sequential record of all committed data modification statements, used primarily for replication and point-in-time recovery. In MySQL and MariaDB,...
Combined Log Format
An extension of the Common Log Format used as the default by Apache HTTP Server and widely adopted by Nginx. Adds referrer...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Log Rotation
The scheduled process of closing the current log file, compressing it, renaming it with a date or sequence suffix, and opening a...
SIEM
Security Information and Event Management. A platform that ingests log streams from multiple sources, normalises them to a common schema, and applies...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.