The syslog-ng agent can send the syslog messages using either the ISO or the BSD timestamp format. It is recommended to use the ISO format, because it contains much more information than the BSD format.
Note that in the syslog-ng agent, the macros without prefix (e.g.,
DATE) always refer to the receiving date of the message
(e.g., R_DATE) when it arrived into the event log container,
and are included only for compatibility reasons.
© 2007-2010 BalaBit IT Security
Please send your comments or documentation bugs to: documentation@balabit.com