Re: [logs] RE: syslog/tcp (selp)

From: Bennett Todd (betat_private)
Date: Mon Jan 13 2003 - 06:17:37 PST

  • Next message: Bennett Todd: "Re: [logs] Syslog payload format"

    2003-01-10T20:52:05 Darren Reed:
    > A quick comment on simple-event-log-protocol.txt - what happened
    > to section 3 ?
    > 
    > It appears to go "2. Transport Layer Protocol" then "4.1 SELP
    > Message parts", which seems somewhat odd.
    > 
    > The document doesn't clearly express what the combined end result of all
    > the fields is meant to look like as output.  While the timestamp does come
    > after the PRI field, what about the HOSTNAME field ?
    
    I believe all of the above are addressed by the last paragraph of
    section 1. Introduction:
    
       I DO NOT INTEND TO DUPLICATE [RFC3164] HERE. As such, this memo
       lists only the differences to [RFC3164]. I am using the original
       chapter numbers to list them.
    
    That very definitely seems to me like the right approach to be
    taking at this point. If ever we decide we want to try to push this
    through IETF into a real RFC (and I wouldn't begin to try until we
    can demonstrate, with a load of working implementations while there
    are none for RFC 3195, that the gap between 3164 and 3195 needs
    filling in), then might be the time to do a merge of 3164 and
    selp.txt to produce a standalone spec.
    
    -Bennett
    
    
    

    _______________________________________________ LogAnalysis mailing list LogAnalysisat_private http://lists.shmoo.com/mailman/listinfo/loganalysis



    This archive was generated by hypermail 2b30 : Mon Jan 13 2003 - 09:46:32 PST