RE: [logs] Syslog payload format

From: Frank O'Dwyer (fodat_private)
Date: Tue Jan 14 2003 - 08:44:37 PST

  • Next message: wolfgangat_private: "Re: [logs] Syslog payload format"

    Ron Ogle wrote:
    > Like I said before, it would be
    > amazing if Ethernet, IP, TCP, UDP, etc. would have survived you guys.  You
    > can have all kinds of tools that can take this nice efficient log and show
    > you pretty pictures later on the log server.
    
    Nice? Efficient? You've got to be kidding!
    
    If TCP/IP had been designed using the same principles as syslog, then there
    would be no Internet and we would not be having this discussion, because:
    
    * half the data would never show up
    * the network address would be missing
    * the IP address would be written in english as "please send this packet to
    one-hundred-and-twenty"
    * Or completely differently if the developer felt like it, or made a typo.
    
    There are two kinds of simple - simple/elegant and simple/broken. Syslog is
    a model example of the latter.
    
    Cheers,
    Frank
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Tue Jan 14 2003 - 10:21:21 PST