Syslog Message Decoder
Decode a syslog line: PRI value into facility and severity, RFC 3164 or RFC 5424 structure, timestamp and message body.
Result
Decoding
- Calculation
- PRI = facility × 8 + severity → 16 × 8 + 6 = 134
- Facility name
- local0
- Severity keyword
- info
- Operational response
- The bulk of normal volume.
RFC 3164 fields
- Timestamp
- Jul 24 22:15:03
- Hostname
- rtr-core-01
- Message
- %LINK-3-UPDOWN: Interface GigabitEthernet0/1, changed state to down
Cisco message structure
- Cisco facility
- LINK
- Cisco severity
- 3 (err)
- Mnemonic
- UPDOWN
Severity levels
| # | Keyword | Meaning | Typical response |
|---|---|---|---|
| 0 | emerg | System unusable | Page someone now. |
| 1 | alert | Action required immediately | Page someone now. |
| 2 | crit | Critical condition | Hardware failure, ticket immediately. |
| 3 | err | Error condition | Alert - something is broken. |
| 4 | warning | Warning condition | Investigate during working hours. |
| 5 | notice | Normal but significant | Config change, interface flap. |
| 6 | info | Informational | The bulk of normal volume. |
| 7 | debug | Debug-level | Never leave enabled to a remote collector. |
About Syslog Message Decoder
Every syslog message starts with a PRI value that packs facility and severity into one number. Decoding it by hand is easy arithmetic and easy to get wrong at 3am, and knowing whether a line is RFC 3164 or RFC 5424 decides whether your collector will parse it at all.
Getting reliable delivery
Plain syslog over UDP has no acknowledgement, no ordering and no delivery guarantee: under load the messages you most need are the ones dropped. RFC 6587 defines syslog over TCP and RFC 5425 defines it over TLS on port 6514, which adds confidentiality and authentication as well as reliability. Pair either with a disk-backed queue on the sender so a collector restart does not lose the window, and expect a modest CPU cost on the device for TLS.
PRI arithmetic
PRI = facility × 8 + severity. So <134> is facility 16 (local0) and severity 6 (info); <191> is the maximum, local7 debug. Facilities 16-23 (local0-local7) are the ones network equipment uses, which is why filtering by facility is how you separate router logs from host logs on a shared collector.
Common use cases
- Working out why a collector filter is dropping messages you expected.
- Reading a raw capture of syslog traffic during a logging problem.
- Confirming a device is sending at the severity you configured.
Edge cases and gotchas
- RFC 3164 timestamps carry no year and no timezone - correlation across devices depends on all of them agreeing via NTP.
- Plain syslog is UDP: messages are silently lost under load. Use TCP or TLS (6514) for anything you need to rely on.