3 ms·
It seems worth noting that the "Syslog message format" was introduced in RFC 5424; the article cites RFC 3164 for message delivery (and should be citing RFC 542
by beefhash 7y ago
It seems worth noting that the "Syslog message format" was introduced in RFC 5424; the article cites RFC 3164 for message delivery (and should be citing RFC 5424 based on the format).
RFC 5424 defines a more formal and more complete version of the protocol. NetBSD understands and emits it, FreeBSD is still in the process of gaining support for it and OpenBSD seems to be perfectly content sticking to traditional BSD syslog as recorded in RFC 3164.
- viraptor 7y agoAre there any systems apart from hardware appliances that actually care about the "new" syslog format? I'm running into custom aggregator agents, fluentd, and trivial forwarders everywhere. I don't think I've seen structured syslog or the extended metadata properly used anywhere.
- imglorp 7y agoSince we're mentioning some of that newer tech, it might bear bringing up things like http://jsonlines.org http://jsonlines.org for log shipping. If your destination is an ELK stack, this lets you do some neat stuff like adding arbitrary fields in the log shipper and then filter on them in the backend.
- GordonS 7y agoYes, most SIEMs and log management systems support the new format, even if they also push their own proprietary format.
- DominoTree 7y agoAnd let's not forget that there are non-standard "syslog" implementations that were being used for decades before RFC3164 happened. Cisco devices and AIX are the first two big ones that come to mind. It's also worth mentioning that newlines are significant in TCP syslog (for batching log messages) but not in UDP syslog (because of frame size limits)
- astrobe_ 7y ago> It's also worth mentioning that newlines are significant in TCP syslog (for batching log messages) but not in UDP syslog (because of frame size limits) More because of the D in UDP, I believe. UDP is a packet (datagram) protocol; TCP is a stream protocol.
- cat199 7y ago> And let's not forget that there are non-standard "syslog" implementations that were being used for decades before RFC3164 happened. totally agree these exist and may vary wildly - many of these are often proprietary forks of the BSD version in some level of (un)maintained state, FWIW