Re: Error messages from syslogd
Raffael Marty <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
I think this is a beautiful discussion. What is logged? AND how is it logged? Do you log all error situations? You know what, you probably should! But then I want those messages to be of a certain format! (or with a certain categorization / taxonomy associated). That would enable me to filter them, if I am really not interested in them. Some applications know the concept of a log level. Unfortunately, this concept is not really well defined, nor well supported. It would allow the user to choose how much detail he needs! I am a big supporter of logging more. On the other hand, I am a big fan of being able to classify events and selectively use what I need! One of the sub-efforts of CEE is going to be to define _what_ applications should log. I think this discussion will very nicely fold into that! Thanks -raffy -- Raffael Marty Not Chief Logging Evangelist > HOWEVER, I have a different view on service startup. My projects, too, > log things like bind errors IF they happen during service startup. In > the spirit of what I have said before, they still continue to run and > perform as much work as possible. For example, if I can't bind the TCP > port, I can still listen to incoming UDP messages. While I lose TCP, I > do not lose everything (so this is preferred). And you may argue > rightfully that the logging subsystem should try to recover, e.g. by > re-trying the bind somewhat later (I am doing this partly, but have not > yet reached the goal 100%). In any case, I think it is useful to log > those kind of errors when they occur in a very early phase of subsystem > initialization. I fear if I do not log them to the system log, nobody > well ever find the reason, because who looks for a crashdump if it is a) > unusual to happen b) at a remote location c) there is no failure > indication in your log. -- Raffael Marty, GCIA, CISSP [email protected] Manager Strategic Application Solutions ArcSight, Inc. +1 (408) 864 2662 Security Data Visualization: http://secviz.org