Skip to content

Glossary

RFC 5424 (syslog protocol)

The current syslog protocol format, with a version number, a full timestamp with time zone, and structured data, used mainly by forwarders and collectors.

RFC 5424 (2009) defines the current syslog protocol. A message has a fixed header: a priority in angle brackets, the protocol version 1, an RFC 3339 timestamp with fractional seconds and a UTC offset, the host name, the application name, the process ID, a message ID, then structured data and the free-text message. Missing header fields are written as -, the NILVALUE.

The priority encodes facility and severity as facility × 8 + severity: <38> is facility 4 (auth) and severity 6 (info). Structured data is a list of bracketed elements such as [origin ip="192.0.2.20"] that carry key-value pairs alongside the text.

Why it matters in investigations

Unlike RFC 3164, the timestamp carries its year and offset, so no year inference or time-zone guess is needed. You mostly meet RFC 5424 in logs received by central collectors and SIEM forwarders, often over TCP or TLS, rather than in files written locally on the host. Those copies are valuable: they left the machine when the event happened, so an intruder with root on the host cannot edit them. Comparing forwarded RFC 5424 messages with the host's own auth.log is one way to show that a local file was changed. Keep in mind that the host name, application name and PID are still supplied by the sender.

Example

<38>1 2026-09-14T10:02:11.482Z fin-jump-01 sshd 3071 - - Accepted password for svc_backup from 203.0.113.45 port 51544 ssh2

Priority 38 (auth.info), version 1, a UTC timestamp, host fin-jump-01, application sshd, PID 3071, no message ID and no structured data (- -), then the message. rsyslog produces this layout with its RSYSLOG_SyslogProtocol23Format template.

  • RFC 3164: the traditional format without year or zone.
  • rsyslog: a common sender and receiver of RFC 5424.

Linux Log Parser reads RFC 3164, RFC 3339 and RFC 5424 lines. See the pillar guide.