RE: [logs] idea: let's scare ourselves...

From: Rainer Gerhards (rgerhards@private)
Date: Thu Aug 26 2004 - 03:46:27 PDT


> > >There's something in-between: using the BSD syslog 
> protocol on the top
> > >of TCP, with some slight changes:
> > 
> > Pix supports this, Kiwi syslog supports it, syslog-ng supports
> > it, etc. Hmm.... Sounds like a "rough consensus and running code."
> 
> There was some documentation as well, called SELP which stands for
> Simple Enhanced Logging Protocol (strictly IIRC).

Well... actually I was the one who wrote that spec some time ago. It got
a lot of good feedback. Obviously, I've still have it at hand. If the
implementors on this list (at least say syslog-ng, Kiwi and Adiscon
[me;)]) agree, I can pull it out of the archive, give it a brush-up it
then let's have a quick discussion. If the rest of this group thinks
this is useful, I think we should do it. As these 3 implementations are
very close together, I think implementation should be done in a snap...

Rainer
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Fri Aug 27 2004 - 10:35:24 PDT