This sample, generated
The block below is 15 lines of RFC 5424 syslog, produced by the real generator at seed 42 — deterministic, so this exact output regenerates anywhere. The live tool re-runs the identical engine on whatever source, seed, line count and anomalies you pick.
no anomalies injected — raise a slider to seed detectable patterns
Generated RFC 5424 syslog
Real on-the-wire RFC 5424 syslog — no real users, IPs, or secrets. Copy it into a fixture, feed it to a parser, or seed a SIEM demo.
With an anomaly injected: SSH brute-force
The same source, regenerated with a SSH brute-force injected at 30% intensity. 6 line sare tagged and highlighted below — A burst of failed logins from one source IP, then a success — the classic credential-stuffing signature. It is a documented, detectable pattern your SIEM rules should fire on — build the test data, then prove your detection works.
FAQ
- Are these real RFC 5424 messages?
- No — the output is synthetic. It reproduces the RFC 5424 structure exactly (PRI, version 1, ISO 8601 timestamp, hostname, app-name, procid, NILVALUE msgid and structured data, message), but every value is fabricated. Safe for fixtures, demos and receiver conformance tests.
- Can I inject anomalies?
- Yes. Raise any of the five sliders; for a syslog source an SSH brute-force or port-scan pattern is appended in faithful grammar, with the injected lines highlighted and badged so you can verify detection.
- Is the output deterministic?
- Yes — fully seeded. The same seed and config always produce byte-identical RFC 5424 lines, so a committed seed regenerates the identical log on any machine or in CI.
Generate other log sources
- nginx access logs
- Apache access logs
- sshd / OpenSSH auth logs
- RFC 3164 (BSD) syslog
- FortiGate firewall logs
- Cisco ASA firewall logs
- Windows Security Event logs
- JSON application logs
- Docker container logs
- Kubernetes (klog) logs
- AWS VPC Flow logs
Open the LogAnvil generator to tune the seed, line count, EPS, format and anomaly sliders — or build a parser with LogForge for a log you already have.
Generate your own RFC 5424 syslog
Pick the seed, line count and EPS, inject the anomalies your rules should catch, and copy or download the result. Free, no account, nothing uploaded — generation runs entirely in your browser.
Open the LogAnvil generator →