skip to content

A firewall's syslog message begins with <134>; how do you decode that PRI value into a facility and a severity?

level: middleimportance: must knowfreq 35%

answer

  1. two values, one number
  2. multiply, then add
  3. divide by eight
  4. local0 starts at sixteen

basics

~20 s

PRI is facility times 8 plus severity, so divide by 8: the quotient is the facility, the remainder the severity. 134 = 16 x 8 + 6, which is facility 16 (local0) and severity 6 (Informational).

solid answer

~40 s

The number between the angle brackets is the **Priority value**, computed as `facility * 8 + severity`. Decoding reverses it: `134 / 8` is 16 remainder 6, so the message is facility 16, local use 0 (`local0`), at severity 6, Informational. Multiplying by 8 simply puts the severity in the low three bits: 134 is binary `10000110`, high bits `10000` = 16, low bits `110` = 6. Since facilities run 0-23 and severities 0-7, a valid value lies between 0 and 191, written with no leading zeros except `<0>`. Relays and collectors sort on this number; an RFC 3164 relay that finds no valid PRI inserts `<13>`, user-level at Notice.

go deeper

for a junior

Remember the formula facility times 8 plus severity, and that dividing by 8 gives the facility with the remainder as severity. Practise on 134 and 131.

for a middle

Explain why the factor is 8, the 0 to 191 range, the no-leading-zero rule, and that RFC 5424 kept PRI unchanged so older receivers can still sort new-format messages.

for a senior

Discuss PRI as the routing key relays and collectors act on, what an RFC 3164 relay does with a missing or malformed PRI, and how a misparsed PRI silently misfiles urgent messages.

for a principal

Decide how PRI values are allocated across an estate, which local-use facilities map to which device classes, so routing and retention can key on facility without per-vendor parsing.

## The formula Every syslog message starts with a **PRI** part: a `<`, one to three decimal digits, and a `>`. The digits are the **Priority value** (PRIVAL), and RFC 5424 section 6.2.1, like RFC 3164 before it, defines it as: `PRIVAL = facility * 8 + severity` The **facility** (0-23) says what kind of source produced the message; the **severity** (0 Emergency to 7 Debug) says how urgent the originator considers it. One number carries both, and a relay or collector can sort a message by reading only its first few characters. ## Decoding, step by step 1. Strip the angle brackets: `<134>` gives 134. 2. Integer-divide by 8 for the facility: 134 div 8 = 16. 3. Take the remainder for the severity: 134 mod 8 = 6. 4. Look both up: facility 16 is local use 0 (`local0`); severity 6 is Informational. Check it by encoding again: 16 x 8 = 128, plus 6 = 134. | PRI | Facility | Severity | Reading | |---|---|---|---| | `<134>` | 16 local0 | 6 Informational | a routine firewall record | | `<131>` | 16 local0 | 3 Error | same source, far more urgent | | `<190>` | 23 local7 | 6 Informational | another local-use source | | `<34>` | 4 security/authorization | 2 Critical | RFC 5424's own example | | `<165>` | 20 local4 | 5 Notice | RFC 5424's own example | | `<0>` | 0 kernel | 0 Emergency | the only value written with a leading 0 | When the firewall pair in an incident sends both `<134>` and `<131>`, the facility is identical and only the low three bits differ: the second message is an Error, the first is routine. ## Why times eight Severity has eight values, which is exactly three bits. Multiplying the facility by 8 shifts it left by three bits, so the encoding is a bit field: 134 is binary `10000110`, the upper bits `10000` are 16 and the lower bits `110` are 6. Reading the PRI as decimal digits ("1, 3, 4") is meaningless; only the arithmetic, dividing by 8 or masking the low three bits, recovers the two values. ## The encoding rules - The PRI part is three, four or five characters including the brackets, so PRIVAL has one to three digits. - Facility must be 0-23 and severity 0-7, so the largest valid PRIVAL is 23 x 8 + 7 = 191; RFC 5424's grammar states the range 0 to 191. - Leading zeros are forbidden: "0" may follow the `<` only for the value 0 itself, so `<0134>` and `<00>` are not valid PRIs. - RFC 5424 kept PRI unchanged from BSD syslog on purpose. Its Appendix A.1 notes that the one thing all legacy implementations agreed on was that a message starts with `<` PRIVAL `>`, so an older receiver can still sort a new-format message into the right bin. A guarded decoder makes the rules concrete: ``` function decodePri(text): close = indexOf(text, ">") if text[0] != "<" or close not in {2, 3, 4}: return INVALID digits = text[1 .. close - 1] if not allDecimal(digits): return INVALID if length(digits) > 1 and digits[0] == "0": return INVALID value = toInteger(digits) if value > 191: return INVALID return (facility = value div 8, severity = value mod 8) ``` Tracing it: `<134>` closes at index 4 and yields (16, 6); `<00>` fails the leading-zero check; `<192>` fails the range check. ## What relays do with PRI RFC 3164, the Informational document that described BSD syslog and is now obsoleted by RFC 5424, gave relays PRI-driven rules: - Relays must be configured to forward packets on the basis of their Priority value. - A message with a valid PRI and a valid TIMESTAMP is forwarded without any change. - A message with no PRI, or one the relay cannot identify such as `<00>`, gets a new PRI of `<13>` (facility 1 user-level, severity 5 Notice) plus the relay's own TIMESTAMP and, recommended, a HOSTNAME; the whole original becomes the message content. - If the insertion pushes the packet past 1024 bytes, the relay truncates it to 1024, losing the end of the original. RFC 5424 itself does not specify relay behaviour, but the PRI arithmetic is identical in both formats. Whichever format arrives, decode by division, then check the value is in range before trusting either half.

  • What does an RFC 3164 relay do with a message whose PRI it cannot identify, such as <00>?
    It inserts a PRI of `<13>`, which is facility 1 (user-level) at severity 5 (Notice), plus a TIMESTAMP of its own current local time and, recommended, a HOSTNAME. The entire received packet becomes the CONTENT of the relayed message. If that pushes the packet beyond 1024 bytes it must truncate to 1024, losing the end of the original.
  • Why can a syslog PRI value never exceed 191?
    Facility is limited to 0-23 and severity to 0-7, so the largest possible value is 23 x 8 + 7 = 191. RFC 5424's grammar states the PRIVAL range as 0 to 191, so a PRI like `<192>` cannot be decoded into a valid facility and severity.

saying these in an interview costs you the question

  • The PRI is simply the facility plus the severity added together.
  • The first digit of the PRI is the severity and the rest is the facility.
  • Writing <0134> is an acceptable zero-padded form of the PRI.
  • Any three-digit number up to 999 is a valid PRI.
  • RFC 5424 replaced the PRI with separate facility and severity fields.