This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Syslog messages format

Why, when I send to Kiwi Syslog Server a message like "<25>Jul 10 18.04.33 Hostname Appname Message", it only understand the priority, but the timestamp and hostname has ignored and the log look like "2015-07-10 18:04:33 127.0.0.1 Daemon.Alert Jul 10 18.04.33 Hostname Appname Message"

  • I am still new to SolarWinds products, but all the documentation I have found specify RFC3164 for the Syslog message specification. The RFC is very specific on the format of the TIMESTAMP field, it much use ':' as delimiters within the timestamp. The hostname or IP address is fine. If you want to create TAG field for the Appname, then it will need to end with a ':' character; otherwise Appname is assumed to be part of the MESSAGE text. The RFC specifies all the minute details. Try the following and see if this helps...

    <25>Jul 10 18:04:33 Hostname Appname: Message