The Syslog Protocol
RFC 5424, “The Syslog Protocol”, is a Proposed Standard document published in March 2009 by R. Gerhards. It obsoletes RFC 3164. The canonical text is published by the RFC Editor.
Abstract
This document describes the syslog protocol, which is used to convey event notification messages. This protocol utilizes a layered architecture, which allows the use of any number of transport protocols for transmission of syslog messages. It also provides a message format that allows vendor-specific extensions to be provided in a structured way.
This document has been written with the original design goals for traditional syslog in mind. The need for a new layered specification has arisen because standardization efforts for reliable and secure syslog extensions suffer from the lack of a Standards-Track and transport-independent RFC. Without this document, each other standard needs to define its own syslog packet format and transport mechanism, which over time will introduce subtle compatibility issues. This document tries to provide a foundation that syslog extensions can build on. This layered architecture approach also provides a solid basis that allows code to be written once for each syslog feature rather than once for each transport. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 5424 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5423 Internet Message Store Events
- RFC 5425 Transport Layer Security Transport Mapping for Syslog
- RFC 5422 Dynamic Provisioning Using Flexible Authentication via Secure Tunneling Extensible Authentication Protocol
- RFC 5426 Transmission of Syslog Messages over UDP
- RFC 5421 Basic Password Exchange within the Flexible Authentication via Secure Tunneling Extensible Authentication Protocol
- RFC 5427 Textual Conventions for Syslog Management
- RFC 5420 Encoding of Attributes for MPLS LSP Establishment Using Resource Reservation Protocol Traffic Engineering
- RFC 5428 Management Event Management Information Base for PacketCable- and IPCablecom-Compliant Devices