Syslog is a widely used logging protocol in which network devices, servers, and firewalls send their event records in a standard format to a central server. It provides an excellent transport layer for central log collection; however, raw syslog alone is not sufficient for Law 5651 compliance, because the records are unsigned and lack a trusted timestamp. SignLogger collects the syslog stream centrally and signs these records every day, turning them into an archive with real legal evidentiary value.
This content is for general information only and is not a substitute for legal advice. Rely on the applicable legislation and expert opinion for the scope of your obligations.
How Does the Syslog Protocol Work?
Syslog is based on the principle of a source device (router, switch, firewall, server) sending an event message to a central collector configured as a "syslog server." Each message typically carries a facility code, a severity level, timing information, and free-form text. This allows records from hundreds of devices to converge at a single point, making search, correlation, and archiving far easier.
- UDP 514: The classic and most common transport; fast but offers no delivery guarantee or encryption.
- TCP: Connection-based, more reliable transport that reduces the risk of loss.
- TLS (RFC 5425): Provides confidentiality and integrity through encryption in transit.
- Facility / Severity: Classifies messages by their source and criticality.
Why Is Raw Syslog Not Enough for Law 5651?
Under Law No. 5651, hosting providers and mass-use providers are expected to preserve the integrity of the traffic records they generate and the accuracy of the time information. Raw syslog data is weak on both points: a record written to a text file can later be deleted, altered, or have its timing manipulated, with no mechanism to prove otherwise. To qualify as evidence, a record must be independently provable both as "unchanged" and as "existing at that moment."
- No signature: There is no cryptographic guarantee of who produced a raw syslog record or when.
- No trusted timestamp: The device clock may have drifted or been changed manually; the true time of the record cannot be proven.
- Alterability: Plain-text log files are easily edited, and a broken integrity chain goes unnoticed.
- Retention discipline: Continuous, accessible storage for the legally required period is not guaranteed by syslog alone.
SignLogger: Signed Retention on Top of Central Collection
SignLogger collects the standard syslog stream from source devices centrally and signs these records every day with the timestamp and e-signature of TÜBİTAK Kamu SM, an authorized certificate authority. This makes it independently provable both that a record existed at the stated moment and that it has not been altered since. The Kamu SM timestamp service works on a credit (kontör) basis, and SignLogger manages the signing process automatically within this credit model.
SignLogger is brand-independent and works with any RADIUS-capable firewall; it runs on the customer's own infrastructure (VMware/Hyper-V) and the data stays on-premises. For a detailed approach, see our Law 5651 log signing solution.
| Capability | Raw Syslog | Signed Retention with SignLogger |
|---|---|---|
| Central collection | Yes | Yes |
| Cryptographic signature | No | Daily e-signature |
| Trusted timestamp | No | Kamu SM timestamp |
| Proof of integrity | No | Independently verifiable |
| Evidentiary value | Weak | Strong |
| Location | Variable | On-premises |
The Right Setup: Syslog + Signed Archive
There is no need to eliminate syslog; on the contrary, it is valuable as the foundation of central collection. The correct architecture adds a signed, timestamped retention layer on top of the records gathered via syslog. SignLogger provides this layer, giving your records legal evidentiary quality without disrupting your existing network infrastructure. Operational visibility (search, correlation, reporting) and legal retention discipline thus come together in a single system.
Frequently Asked Questions
Does syslog alone provide Law 5651 compliance?
No. Syslog is a good protocol for central collection, but because it contains no signature or trusted timestamp, raw records are not evidence on their own. The records must be stored signed and timestamped.
Does SignLogger replace my existing syslog infrastructure?
No. SignLogger centrally collects the standard syslog stream your devices already send and turns those records into a signed archive. It adds a retention layer on top without disrupting your current network architecture.
How often are the logs signed?
SignLogger signs the records every day using the timestamp and e-signature of the authorized certificate authority TÜBİTAK Kamu SM. This regular signing safeguards the integrity and time accuracy of the records.
Are credits required for the timestamp?
Yes. The Kamu SM timestamp service works on a credit (kontör) basis. SignLogger manages the signing process within this credit model, and credit consumption depends on the volume of records signed.
Where is my data stored?
SignLogger runs on the customer's own infrastructure (VMware/Hyper-V), and all logs remain on-premises. Your data is not transferred to an external cloud.
Which devices does it work with?
SignLogger is brand-independent and works with any firewall or network device that can produce syslog or supports RADIUS; it is not tied to a specific manufacturer.