398
C
16: N
HAPTER
ETWORK
Header Component
M
ANAGEMENT
Table 74 Facilities Mapped to the System Log Handles
Log Handles
Adminlog
SNMP traps
The current administration log messages are classified to only one facility;
that is, log.
The Priority value is calculated as follows:
1 Multiplying the Facility number by the number eight
2 Adding the numerical value of the Severity
Examples:
A kernel message (Facility=0) with a Severity of Emergency
■
(Severity=0) has a Priority value of zero (0).
A
■
local use 4
(Severity=5) has a Priority value of 165.
In the PRI part of a Syslog message, these values would be placed
between the angle brackets as <0> and <165, respectively. The only
time a value of zero follows the less-than character is when the Priority
value is zero. Otherwise, leading zeroes must not be used.
The Header component of the Syslog message must contain the
following:
A timestamp
■
An indication of the hostname or IP address of the device
■
Visible (printing) characters
■
A seven-bit ASCII code set in an eight-bit field like that used in the PRI
■
part.
In this code set, the only allowable characters are the ABNF VCHAR
values (%d33-126) and spaces (SP value %d32).
The Header contains two fields called the TIMESTAMP and the
HOSTNAME.
Numerical Code Facility
13
log audit(note1)
14
log alert(note1)
message (Facility=20) with a Severity of Notice