Syslog Message Decoder

Decode a syslog line: PRI value into facility and severity, RFC 3164 or RFC 5424 structure, timestamp and message body.

Calculator Syslog & Logs Runs in your browser
Paste a full line, or just a number like 134.
Try:

Result

PRI
134
Facility
16 (local0)
Severity
6 (info)
Meaning
Informational
Format
RFC 3164 (BSD legacy)

Decoding

Calculation
PRI = facility × 8 + severity → 16 × 8 + 6 = 134
Facility name
local0
Severity keyword
info
Operational response
The bulk of normal volume.

RFC 3164 fields

Timestamp
Jul 24 22:15:03
Hostname
rtr-core-01
Message
%LINK-3-UPDOWN: Interface GigabitEthernet0/1, changed state to down

Cisco message structure

Cisco facility
LINK
Cisco severity
3 (err)
Mnemonic
UPDOWN

Severity levels

#KeywordMeaningTypical response
0emergSystem unusablePage someone now.
1alertAction required immediatelyPage someone now.
2critCritical conditionHardware failure, ticket immediately.
3errError conditionAlert - something is broken.
4warningWarning conditionInvestigate during working hours.
5noticeNormal but significantConfig change, interface flap.
6infoInformationalThe bulk of normal volume.
7debugDebug-levelNever leave enabled to a remote collector.

About Syslog Message Decoder

Every syslog message starts with a PRI value that packs facility and severity into one number. Decoding it by hand is easy arithmetic and easy to get wrong at 3am, and knowing whether a line is RFC 3164 or RFC 5424 decides whether your collector will parse it at all.

Getting reliable delivery

Plain syslog over UDP has no acknowledgement, no ordering and no delivery guarantee: under load the messages you most need are the ones dropped. RFC 6587 defines syslog over TCP and RFC 5425 defines it over TLS on port 6514, which adds confidentiality and authentication as well as reliability. Pair either with a disk-backed queue on the sender so a collector restart does not lose the window, and expect a modest CPU cost on the device for TLS.

PRI arithmetic

PRI = facility × 8 + severity. So <134> is facility 16 (local0) and severity 6 (info); <191> is the maximum, local7 debug. Facilities 16-23 (local0-local7) are the ones network equipment uses, which is why filtering by facility is how you separate router logs from host logs on a shared collector.

Common use cases

  • Working out why a collector filter is dropping messages you expected.
  • Reading a raw capture of syslog traffic during a logging problem.
  • Confirming a device is sending at the severity you configured.

Edge cases and gotchas

  • RFC 3164 timestamps carry no year and no timezone - correlation across devices depends on all of them agreeing via NTP.
  • Plain syslog is UDP: messages are silently lost under load. Use TCP or TLS (6514) for anything you need to rely on.

Frequently asked questions

What facility should network devices use?
local0 through local7 are reserved for local use, and network equipment conventionally uses them. Assign one per device class so a collector can route by facility.
Why do Cisco messages have two severities?
The PRI severity is the syslog transport severity; the number inside %FACILITY-n-MNEMONIC is Cisco's own severity for that message. They usually agree but are set independently.