Glossary
RFC 3164 (traditional syslog format)
The traditional BSD syslog line format, Mmm dd HH:MM:SS host tag: message, in local time with no year and no time zone.
RFC 3164 (2001) documented the BSD syslog protocol as it was used in practice. On the wire a message starts with a priority in angle brackets, followed by a timestamp in the form Mmm dd HH:MM:SS, the host name, a tag (usually the program name and PID) and the message. In log files the priority is normally dropped, which gives the familiar line Sep 14 10:02:11 fin-jump-01 sshd[3071]: ....
rsyslog writes this format with its RSYSLOG_TraditionalFileFormat template. RHEL, Rocky, Alma and Fedora still use it for /var/log/secure and /var/log/messages, as did Debian and Ubuntu releases before Ubuntu 24.04 and Debian 12, which switched to RFC 3339 timestamps with microseconds and an offset.
Why it matters in investigations
The timestamp has no year and no time zone. The time is local to the host, so it must be converted with the zone in /etc/localtime (or /etc/timezone) collected from the same machine. The year has to be inferred from the file's modification time and rotation order, watching for a file that spans New Year: December lines followed by January lines belong to two different years. Around daylight-saving changes, local times can repeat or skip an hour. Get any of this wrong and the lines land in the wrong place in a merged timeline. The tag is also not verified: any local user can write a line claiming to be sshd with logger.
Example
The same event in both formats:
Sep 14 10:02:11 fin-jump-01 sshd[3071]: Accepted password for svc_backup from 203.0.113.45 port 51544 ssh2
2026-09-14T10:02:11.482113+00:00 fin-jump-01 sshd[3071]: Accepted password for svc_backup from 203.0.113.45 port 51544 ssh2
The second, RFC 3339 form needs no inference; the first needs a year and a zone from outside the line.
Related terms
- RFC 5424: the newer syslog protocol with full timestamps.
- rsyslog: the daemon that writes these files.
- systemd journal: stores the same messages in UTC microseconds.
Linux Log Parser infers the year and converts the zone for you. See auth.log forensics.