skip to content

What does an RFC 5424 syslog header carry that the older BSD format described in RFC 3164 lacks, and why does that matter?

level: middleimportance: should knowfreq 30%

answer

  1. a version digit after PRI
  2. the year and the zone
  3. TAG split three ways
  4. brackets of name=value pairs
  5. a hyphen for nothing

basics

~20 s

RFC 5424 adds a VERSION, a timestamp with year, fractional seconds and UTC offset, separate APP-NAME, PROCID and MSGID fields, and STRUCTURED-DATA. RFC 3164 only recorded BSD practice: local time without year or zone, a hostname, then free text.

solid answer

~40 s

RFC 3164 is an Informational document that described what BSD syslog implementations did; RFC 5424 obsoletes it with a Standards Track format. The BSD header is a PRI, a `Mmm dd hh:mm:ss` local time with no year or zone, a hostname, then a TAG of up to 32 characters and free text, the whole packet capped at 1024 bytes. RFC 5424 keeps PRI and adds `VERSION` (1), an RFC 3339 `TIMESTAMP` with year, up to six fractional digits and a `Z` or numeric offset, a HOSTNAME that should be an FQDN, the TAG split into `APP-NAME`, `PROCID` and `MSGID`, and `STRUCTURED-DATA` elements such as `[origin ip="192.0.2.10"]`. Every empty field is the NILVALUE `-`, so fields can be split without guessing and events can be placed in absolute time.

go deeper

for a junior

Know that there are two formats, the old BSD one and RFC 5424, and that the newer one adds a year, a time zone and named header fields.

for a middle

Walk through the RFC 5424 header field by field, the NILVALUE, and SD-ELEMENT syntax including the at-sign rule for private SD-IDs, against RFC 3164's TAG and local timestamp.

for a senior

Explain what is lost when a relay chain mixes formats: guessed years and zones, structured data flattened into text, and how that corrupts incident timelines across devices.

for a principal

Set a format policy for the estate: require RFC 5424 where devices support it, define which structured-data elements every originator must send, and plan for legacy BSD sources.

## Two documents with different status **RFC 3164** (2001) is an **Informational** RFC. It did not design a protocol; it wrote down what BSD-derived syslog implementations were observed to send. RFC 5424 Appendix A.1 is blunt about the result: implementations had very little in common, and the only thing all of them agreed on was that a message starts with `<` PRIVAL `>`. RFC 3164 even says that any packet sent to UDP port 514 must be treated as a syslog message, whatever its contents. **RFC 5424** (2009) is **Standards Track** and **obsoletes RFC 3164**. It defines the message format independently of transport and keeps the PRI exactly as it was, so a legacy receiver can still sort new messages. ## Field by field | Element | RFC 3164 (BSD, observed) | RFC 5424 | |---|---|---| | PRI | `<` facility x 8 + severity `>` | unchanged | | Version | none | `VERSION`, value `1` for this specification | | Timestamp | `Mmm dd hh:mm:ss`, local time, no year, no zone | RFC 3339 form: year, `T`, up to 6 fractional digits, `Z` or `+hh:mm` | | Host | hostname without domain, or an IP address | `HOSTNAME`, preferably an FQDN, max 255 characters | | Program | `TAG`, up to 32 alphanumeric characters, ended by `[`, `:` or space in practice | `APP-NAME` (48), `PROCID` (128), `MSGID` (32) | | Metadata | none | `STRUCTURED-DATA`: zero or more `[SD-ID name="value" ...]` elements | | Text | `CONTENT`, free form | `MSG`, optionally UTF-8 marked by a byte order mark | | Empty field | absent or guessed | the NILVALUE, a single `-` | | Size | packet must be 1024 bytes or less | no upper limit per se; the transport sets the minimum receivers must accept, never under 480 octets | ## The same event in both formats A firewall in the incident pair, `fw-a`, denies a connection: ``` <134>Oct 1 14:03:07 fw-a fwlog[812]: deny tcp 203.0.113.50:51514 to 192.0.2.10:22 <134>1 2026-10-01T14:03:07.412+02:00 fw-a.example.net fwlog 812 DENY [origin ip="192.0.2.10"] deny tcp 203.0.113.50:51514 to 192.0.2.10:22 ``` The first line cannot say which year it is or which zone "14:03:07" belongs to, and a parser has to guess where the program name ends. The second line has fixed, space-separated header fields; the collector knows the instant to the millisecond in absolute time, the message type (`DENY`), and an address the originator vouches for in a registered structured-data element. ## Structured data, precisely - An **SD-ELEMENT** is `[` SD-ID, then zero or more `name="value"` parameters, then `]`. Elements follow each other with **no** space; RFC 5424's own invalid example shows that a space after the first `]` ends STRUCTURED-DATA and turns the rest into MSG. - Inside a value, the characters `"`, `\` and `]` must be escaped with a backslash. - An SD-ID **without** an at-sign must be registered with IANA. RFC 5424 registers `timeQuality`, `origin` and `meta`. - Anyone else uses `name@<private enterprise number>`, for example `fwStats@32473` (32473 is the number reserved for documentation). - With no elements at all, the field is the NILVALUE `-`. A relay must forward malformed structured data without alteration; a collector may ignore it. ## Why it matters on the wire 1. **Absolute time.** A BSD timestamp cannot be placed on a timeline across zones or a year boundary. RFC 5424 Appendix A.1 says that converting an RFC 3164 message adds the current year and may use the relay's or collector's time zone, which is a guess about the originator. 2. **Unambiguous splitting.** Every header field is present, even if only as `-`, so position alone identifies it. 3. **Self-description.** `timeQuality` states whether the clock was synchronised; `meta sequenceId` numbers messages so gaps are visible; `origin` lists the originator's addresses. 4. **Interoperability.** RFC 5424 also says that if a message must be reformatted to RFC 3164, structured data simply becomes part of the free text and the year and zone are dropped, so a downgrade throws information away. 5. **Character sets.** RFC 5424 keeps the header and structured-data names in seven-bit ASCII and allows UTF-8 in parameter values and in MSG, where a byte order mark declares it, so the header fields can be split without decoding any text. How a collector then parses, enriches and routes these fields is a log-pipeline question; the format's job is to make them unambiguous on the wire.

  • What happens to RFC 5424 structured data and timestamps if a relay has to rewrite a message in RFC 3164 format?
    RFC 5424 Appendix A.1 says the structured data simply becomes part of the RFC 3164 free-form content, and the timestamp is rewritten in the originator's local time with the year and time zone dropped. The downgrade loses machine-readable metadata and absolute time, which is why mixed-format relay chains degrade the record.
  • Why is a space between two RFC 5424 SD-ELEMENTs a bug rather than harmless formatting?
    STRUCTURED-DATA is one or more elements written back to back. A space after the first `]` ends the field, so RFC 5424's own invalid example shows the second element being read as part of MSG. The metadata is still on the wire but no longer parsed as structured data.

saying these in an interview costs you the question

  • RFC 3164 is the current syslog standard and RFC 5424 is an optional extension.
  • BSD-format syslog timestamps carry the year and a UTC offset.
  • RFC 5424 structured data is a JSON object placed in the message body.
  • An empty RFC 5424 header field is simply left out of the message.
  • Any vendor may define a bare SD-ID such as fwStats without registering it.