---
title: "BSD-syslog or legacy-syslog messages"
url: "https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-message-structure/concepts-message-bsdsyslog/"
description: "The structure of BSD-syslog (RFC 3164) messages: the PRI, HEADER, and MSG parts."
last_modified: "2026-09-23T14:21:26+02:00"
---

> For the complete documentation index, see [llms.txt](https://axoflow.com/docs/axosyslog-core/4.28/llms.txt).

# BSD-syslog or legacy-syslog messages

The structure of BSD-syslog (RFC 3164) messages: the PRI, HEADER, and MSG parts.

New to AxoSyslog? AxoSyslog is a binary compatible `syslog-ng` replacement, from the original creator, developed by the same team.

Same architecture, same config files, same paths. Cloud-native images, fast releases, modern observability (OTel, K8s), and powerful data processing: read more about the [differences between AxoSyslog and `syslog-ng`](https://axoflow.com/axosyslog-vs-syslog-ng?utm_source=docs&utm_medium=banner).

Also, it’s super easy to [install](https://axoflow.com/docs/axosyslog-core/4.28/install/index.md), and you can [upgrade from `syslog-ng` in minutes](https://axoflow.com/docs/axosyslog-core/4.28/install/upgrade-syslog-ng/index.md).

This section describes the format of a syslog message, according to the [legacy-syslog or BSD-syslog protocol](https://datatracker.ietf.org/doc/rfc3164/). A syslog message consists of the following parts (the examples are taken from the sample message below):

| Part | Example |
| --- | --- |
| [`PRI`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-message-structure/concepts-message-pri/index.md) | `<34>` |
| [`HEADER`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-message-structure/concepts-message-bsdsyslog/index.md#the-header-message-part) | `Oct 11 22:14:15 mymachine` |
| [`MSG`](https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-message-structure/concepts-message-bsdsyslog/index.md#the-msg-message-part) | `su: 'su root' failed for lonvick on /dev/pts/8` |

The total message cannot be longer than 1024 bytes.

The following is a sample syslog message

```shell
<34>Oct 11 22:14:15 mymachine su: 'su root' failed for lonvick on /dev/pts/8
```

The message corresponds to the following format:

```shell
<priority>timestamp hostname application: message
```

The different parts of the message are explained in the following sections.

> **Note:**
> RFC 3164 is lenient about what a message must contain: senders may omit the `PRI` (and sometimes the `HEADER`), and receivers still accept such messages. When a message has no `PRI`, AxoSyslog assigns a default facility and severity (`user.notice`, PRI `13`) — see [The PRI message part](https://axoflow.com/docs/axosyslog-core/4.28/chapter-concepts/concepts-message-structure/concepts-message-pri/index.md).

> **Note:**
> The AxoSyslog application supports longer messages as well. For details, see the `log-msg-size()` option in [Global options reference](https://axoflow.com/docs/axosyslog-core/4.28/chapter-global-options/reference-options/index.md). However, it is not recommended to enable messages larger than the packet size when using UDP destinations.

## The HEADER message part

The `HEADER` message part contains a timestamp and the hostname (without the domain name) or the IP address of the device. The timestamp field is the local time in the *Mmm dd hh:mm:ss* format, where:

- *Mmm* is the English abbreviation of the month: Jan, Feb, Mar, Apr, May, Jun, Jul, Aug, Sep, Oct, Nov, Dec.
- *dd* is the day of the month on two digits. If the day of the month is less than 10, the first digit is replaced with a space. (for example, *Aug 7*.)
- *hh:mm:ss* is the local time. The hour (hh) is represented in a 24-hour format. Valid entries are between 00 and 23, inclusive. The minute (mm) and second (ss) entries are between 00 and 59 inclusive.

> **Note:**
> The AxoSyslog application supports other timestamp formats as well, like ISO, or the PIX extended format. For details, see the [ts-format()](https://axoflow.com/docs/axosyslog-core/4.28/chapter-global-options/reference-options/index.md#global-option-ts-format) global option.

## The MSG message part

The `MSG` part contains the name of the program or process that generated the message, and the text of the message itself. The `MSG` part is usually in the following format: `program[pid]: message text`.

Last modified September 23, 2026: [Adds frontmatter descriptions to top-level sections (a27cc77e)](https://github.com/axoflow/axosyslog-core-docs/commit/a27cc77e261c9a82032e3bd5eb4bb12b6cd51118)
