# Syslog messages from FreeBSD not parsed correctly

**URL:** <https://community.graylog.org/t/syslog-messages-from-freebsd-not-parsed-correctly/19906>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [May 19, 2021, 9:51pm UTC](https://community.graylog.org/t/syslog-messages-from-freebsd-not-parsed-correctly/19906 "2021-05-19T21:51:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![einsibjani](https://avatars.discourse-cdn.com/v4/letter/e/d9b06d/32.png) [@einsibjani](https://community.graylog.org/u/einsibjani)\
**Post date:** [May 19, 2021, 9:51pm UTC](https://community.graylog.org/t/syslog-messages-from-freebsd-not-parsed-correctly/19906/1 "2021-05-19T21:51:23Z")

</div>

I just setup Graylog 4.0 on FreeBSD. To test it I configured a couple of FreeBSD servers to send syslog messages to it. The messages are stored, but they’re not parsed corretly.  
For example, the source field is haproxy[123] (Application name and pid).

If I configure syslogd to use RFC 5424 it’s parsed correctly, but we have different monitoring systems parsing the logs so changing the format is not easy.

I’m guessing something is causing graylog to parse the message as RFC 5424 even though it’s in RFC 3164 format. An example of a log line is:

May 19 21:45:12 stg myapp[88834]: Hello, World

In graylog it looks like:

 ![Screenshot from 2021-05-19 21-49-22](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/a/a94cf5b4cc6db09ab5e0f9797601aa371ed05a6c.png)

What is the simplest way of getting graylog to correctly parse this message, without too drastic changes to the log format on the sending host?

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [May 20, 2021, 10:41am UTC](https://community.graylog.org/t/syslog-messages-from-freebsd-not-parsed-correctly/19906/2 "2021-05-20T10:41:46Z")

</div>

Hi @einsibjani

I’ve tried your input using nc and works as expected, source was parsed correctly to Syslog UDP input:  
`echo -n '<13>May 19 21:45:12 stg myapp[88834]: Hello, World 21:45' | nc -u 172.28.128.15 1515`  
Or Syslog TCP:  
`echo '<13>May 19 21:45:12 stg myapp[88834]: Hello, World 21:45' | nc 172.28.128.15 1516`

Please post which type of input do you use? Syslog TCP or Syslog UDP input? Do you create some extractors or pipeline rules, which should modify parsing?

Try enable `Store full message?` in input to show full message in field `full_message`

---

<div class="post-metadata">

**Author:** ![einsibjani](https://avatars.discourse-cdn.com/v4/letter/e/d9b06d/32.png) [@einsibjani](https://community.graylog.org/u/einsibjani)\
**Post date:** [May 20, 2021, 11:31am UTC](https://community.graylog.org/t/syslog-messages-from-freebsd-not-parsed-correctly/19906/3 "2021-05-20T11:31:43Z")

</div>

Thanks for your help, but we’ve decided to bite the bullet and configure syslogd to use RFC 5424.

If you’re interested, an example of a full\_message is:

\<13\>May 20 11:27:55 myapp[97386]: Hello, World

So syslogd isn’t sending the hostname…

---

<div class="post-metadata">

**Author:** ![einsibjani](https://avatars.discourse-cdn.com/v4/letter/e/d9b06d/32.png) [@einsibjani](https://community.graylog.org/u/einsibjani)\
**Post date:** [May 27, 2021, 8:27am UTC](https://community.graylog.org/t/syslog-messages-from-freebsd-not-parsed-correctly/19906/4 "2021-05-27T08:27:03Z")

</div>

Just in case someone stumbles upon this post looking for a solution, the problem is known with FreeBSD syslogd

[https://bugs.freebsd.org/bugzilla/show\_bug.cgi?id=220246](https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=220246)  
[https://bugs.freebsd.org/bugzilla/show\_bug.cgi?id=194231](https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=194231)

FreeBSD developers have decided that syslogd RFC 3164 compliance has been broken for so long, that they’re afraid to change it now. The workaround is enabling RFC 5424.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [June 10, 2021, 8:27am UTC](https://community.graylog.org/t/syslog-messages-from-freebsd-not-parsed-correctly/19906/5 "2021-06-10T08:27:41Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
