[IDMEF] [Issue 3] additionaldata and meaning
Herve Debar <[email protected]> Thu, 08 Jan 2004 17:35:39 +0100
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Organization | France Telecom R et D |
| Message-ID | <[email protected]> |
Herve> The current tag for introducing additionaldata is the Herve> following: Herve> <additionaldata type=[fixed list] meaning=[free text]> Herve> I propose to specify a non-mandatory list for meaning, Herve> as a best-current-practice, to help convergence on the Herve> description of additional data. I would include "packet-dump" Herve> in the list. DaveC> I thought this had come up before and was rejected by the DaveC> group, although I may be misremembering things. I don't DaveC> have any strong feelings one way or the other. Zaraska> Agreed. This is absolutely necessary. [NOTE: I have splitted the issue in 2, and have included K Zaraska's comment in both, as I believe it adresses the two final issues. My mistake if it does not.] The rationale for proposing such a list is to help interoperability. I see it as a BCP rather than a normative reference. However, I am reluctant to have yet another draft that would be a BCP on how to use the free text in all possible fields of the IDMEF DTD/Schema. So I was hoping that a statement like "MAY use one of the keywords of the following list to represent this kind of information ...." would be acceptable to everybody. Please comment so that we can reach a concensus. BTW, if we moved to schemas, my understanding is that we could then have an (extensible) namespace there. Am I right ? Hervé -- Hervé Debar <mailto:[email protected]> Tel: +33 (0)2 31 75 92 61 GSM: +33 (0)6 74 09 09 66 France Télécom R&D Fax: +33 (0)2 31 75 93 13 42 rue des Coutures (--) BP 6243 (--) F-14066 Caen Cedex 4