Syslog PRI decoder

Decode the <PRI> at the start of a syslog message into facility and severity, or work out the PRI for a facility and severity.

Reference: severities

CodeKeywordSeverityMeaning
0emergEmergencySystem is unusable
1alertAlertAction must be taken immediately
2critCriticalCritical conditions
3errErrorError conditions
4warningWarningWarning conditions
5noticeNoticeNormal but significant condition
6infoInformationalInformational messages
7debugDebugDebug-level messages

Reference: facilities

CodeKeywordDescription (RFC 5424)
0kernKernel messages
1userUser-level messages
2mailMail system
3daemonSystem daemons
4authSecurity/authorization messages
5syslogMessages generated internally by syslogd
6lprLine printer subsystem
7newsNetwork news subsystem
8uucpUUCP subsystem
9cronClock daemon
10authprivSecurity/authorization messages
11ftpFTP daemon
12noneNTP subsystem
13noneLog audit
14noneLog alert
15noneClock daemon
16local0Local use 0
17local1Local use 1
18local2Local use 2
19local3Local use 3
20local4Local use 4
21local5Local use 5
22local6Local use 6
23local7Local use 7

How it works

PRI is facility × 8 + severity, so valid values run from 0 to 191. The decoder also tells you whether the rest of the line looks like RFC 5424 (a version number follows the PRI) or the older BSD / RFC 3164 style (a timestamp follows it).

Facility keywords follow the common glibc names. Facilities 12 to 15 have no portable keyword, so only their RFC 5424 description is shown.

Useful when a log source lands with the wrong severity or facility in a SIEM and you want to confirm what the device actually sent.

All tools

Search the site