Syslog PRI decoder
Decode the <PRI> at the start of a syslog message into facility and severity, or work out the PRI for a facility and severity.
Work out a PRI
PRI
Reference: severities
| Code | Keyword | Severity | Meaning |
|---|---|---|---|
| 0 | emerg | Emergency | System is unusable |
| 1 | alert | Alert | Action must be taken immediately |
| 2 | crit | Critical | Critical conditions |
| 3 | err | Error | Error conditions |
| 4 | warning | Warning | Warning conditions |
| 5 | notice | Notice | Normal but significant condition |
| 6 | info | Informational | Informational messages |
| 7 | debug | Debug | Debug-level messages |
Reference: facilities
| Code | Keyword | Description (RFC 5424) |
|---|---|---|
| 0 | kern | Kernel messages |
| 1 | user | User-level messages |
| 2 | mail | Mail system |
| 3 | daemon | System daemons |
| 4 | auth | Security/authorization messages |
| 5 | syslog | Messages generated internally by syslogd |
| 6 | lpr | Line printer subsystem |
| 7 | news | Network news subsystem |
| 8 | uucp | UUCP subsystem |
| 9 | cron | Clock daemon |
| 10 | authpriv | Security/authorization messages |
| 11 | ftp | FTP daemon |
| 12 | none | NTP subsystem |
| 13 | none | Log audit |
| 14 | none | Log alert |
| 15 | none | Clock daemon |
| 16 | local0 | Local use 0 |
| 17 | local1 | Local use 1 |
| 18 | local2 | Local use 2 |
| 19 | local3 | Local use 3 |
| 20 | local4 | Local use 4 |
| 21 | local5 | Local use 5 |
| 22 | local6 | Local use 6 |
| 23 | local7 | Local use 7 |
How it works
PRI is facility × 8 + severity, so valid values run from 0 to 191. The decoder also tells you whether the rest of the line looks like RFC 5424 (a version number follows the PRI) or the older BSD / RFC 3164 style (a timestamp follows it).
Facility keywords follow the common glibc names. Facilities 12 to 15 have no portable keyword, so only their RFC 5424 description is shown.
Useful when a log source lands with the wrong severity or facility in a SIEM and you want to confirm what the device actually sent.