Re: [logs] Syslog payload format

From: Balazs Scheidler (bazsiat_private)
Date: Tue Dec 31 2002 - 00:20:23 PST

  • Next message: Darin.MARAISat_private: "[logs] FW: ps. need help with some tools for log analogy"

    On Mon, Dec 30, 2002 at 07:32:32PM -0500, Marcus J. Ranum wrote:
    > Balazs Scheidler wrote:
    > >xnewsyslog(LOG_DAEMON | LOG_INFO, 
    > >           "User logged in", 
    > >           "%(user)s %(tty)s %(host)s",
    > >           "marcus", "ttyp6", host);
    > 
    > This is horrible. You're basically doing the same thing as
    > "old" syslog: you're sticking arbitrary strings out there with
    > no mark-up regarding their semantics.
    > 
    > Right now the assembled log-weenies of the world are fighting
    > a battle (that is about to become hugely expensive) to apply
    > significance (i.e.: semantic value) to log data. Continuing to
    > encourage client-side APIs that are devoid of additional
    > semantic data is not helping anything. We may as well stick
    > with stupid old syslog (but fix the transports) and call it sucky
    > enough.
    
    Limiting the number of possible markups with a fixed set without the
    possibility of extension will not help the world either.
    
    Maybe we can start gathering MIBs for log tags ?
    
    -- 
    Bazsi
    PGP info: KeyID 9AF8D0A9 Fingerprint CD27 CFB0 802C 0944 9CFD 804E C82C 8EB1
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Tue Dec 31 2002 - 15:16:32 PST