Re: [logs] RE: syslog/tcp (selp)

From: Darren Reed (avalonat_private)
Date: Thu Jan 09 2003 - 17:09:00 PST

  • Next message: Frank O'Dwyer: "RE: [logs] syslog/tcp (selp)"

    In some mail from Andrew Ross, sie said:
    > 
    > 
    > SELP 0000 <PRI> HOSTADDRESS MESSAGE.
    > 
    > Can we also specify that the HOSTADDRESS MUST be an address rather than
    > a resolved name? It makes parsing easier and means we can do filtering
    > on hosts a lot easier.
    
    How about name AND address ?  Both have meaning at the time, that can be
    lost when you try to do analysis later, based on one or the other.
    
    Darren
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Fri Jan 10 2003 - 09:44:54 PST