. . . . .
L O G G I N G
Syslog Management
Version 3R2
Security Appliance User Guide
6-9
SYSLOG MESSAGE FORMAT
When the security appliance generates and sends syslog messages for
delivery to the syslog server, the format for the messages is standard.
SYSLOG MESSAGE SAMPLE:
192.168.65.230: <134>Jun 02 12:13:54 2006 vendor name
id=security_appliance policy[117] [INFO] id=1 proto=1
src=64.62.250.2:0 dst=64.79.127.67:0 packet dropped due
to policy deny
Table 6-1
shows the syslog message format.
Table 6-1: Syslog Message Format
Field Example
Field Name
Description
Jun 02
Month and Day
Stamp
Displays the month and day
when the message was
generated.
12:13:54
Time stamp
Displays the time stamp
when the message was
generated. The format is as
follows HH:MM:SS.
2006
Year Stamp
Displays the year when the
message was generated.
Vendor name
Device name
Displays the vendor name.
Security_Appliance
Device id
Displays the hostname for
the appliance.
Policy
Software module
name
Displays the software
module name that
generated the log message.
[117]
Software module
process ID
Displays the software
module process ID that
generated the log message.
INFO
Log level
Displays the log severity
level.
ID=1
Device ID
Displays the ID number of
the device.
Proto=1
Protocol number
Displays the protocol or
service number.