Re: How to define Log, Event, and Alert?
"Jon Stearley" <[email protected]> Wed, 23 Jul 2008 15:43:27 -0600
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
--===============1769887479== Content-Type: multipart/alternative; boundary=Apple-Mail-48-171522978 --Apple-Mail-48-171522978 Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset=us-ascii; delsp=yes; format=flowed > > Log (n): > The record comprising one or more log entries accumulated over > a given period. This may be electronic (e.g. stored in memory, disk, > software, database, text file, etc), physical (e.g. on paper), or even > verbal (e.g., "Between 10:00 and 10:01 we received a series of several yes verbal if and only if it is a reviewable record, eg recorded. > What do you think? key aspects of a log are that it describe 1) what happened and 2) when. i think "log entry" is clearer than "message" from rfc3164. so a log is one or more log entries, log entries may indicate events, and events may warrant alerts. seems good to me. -jon --Apple-Mail-48-171522978 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=iso-8859-1 <html><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; = -webkit-line-break: after-white-space; "><div><blockquote = type=3D"cite"><div style=3D"margin-top: 0px; margin-right: 0px; = margin-bottom: 0px; margin-left: 0px; min-height: 14px; = "><br></div></blockquote></div><div><blockquote type=3D"cite"><div = style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; = margin-left: 0px; ">Log (n):</div><div style=3D"margin-top: 0px; = margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">=A0 =A0 =A0 = =A0=A0The record comprising one or more log entries accumulated = over</div><div style=3D"margin-top: 0px; margin-right: 0px; = margin-bottom: 0px; margin-left: 0px; ">a given period. This may be = electronic (e.g. stored in memory, disk,</div><div style=3D"margin-top: = 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; = ">software, database, text file, etc), physical (e.g. on paper), or = even</div><div style=3D"margin-top: 0px; margin-right: 0px; = margin-bottom: 0px; margin-left: 0px; ">verbal (e.g., "Between 10:00 and = 10:01 we received a series of = several</div></blockquote><br></div><div>yes verbal if and only if it is = a reviewable record, eg recorded.</div><div><br></div><div><blockquote = type=3D"cite"><span class=3D"Apple-style-span" = style=3D"-webkit-text-stroke-width: -1; ">What do you = think?</span></blockquote><div><font class=3D"Apple-style-span" = color=3D"#0000DD"><span class=3D"Apple-style-span" = style=3D"-webkit-text-stroke-width: -1;"><br = class=3D"webkit-block-placeholder"></span></font></div></div><div>key = aspects of a log are that it describe 1) what happened and 2) = when.</div><div><br class=3D"webkit-block-placeholder"></div><div>i = think "log entry" is clearer than "message" from rfc3164.</div><div><br = class=3D"webkit-block-placeholder"></div><div>so a log is one or more = log entries, log entries may indicate events, and events may warrant = alerts. =A0seems good to me.</div><div><br = class=3D"webkit-block-placeholder"></div><div>-jon</div></body></html>= --Apple-Mail-48-171522978-- --===============1769887479== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis --===============1769887479==--