Forum Discussion

8 years ago

Syslog Timestamps and RFC's

Syslog issues:

1. Being bound to only the two RFC for syslog is near sighted:   syslog / timestamp / formatting should be more flexible.

2.  the biggest concern I have is that Syslog should reflect the time stamp of the COLLECTOR'S NIC at the time the syslog packet ARRIVES at the collector....not the syslog / timestamp of the system sending the message :  this is especially important with systems where clock settings or NTP are currently failing......alerting is based on the time stamp :  if the time stamp says Jan 1st 2001 12:01am  becasue the CMOS battery on the unit failed......than we NEVER see those syslog messages due to alerting range.