[IDMEF][Issue 9] Alert routing

Herve Debar <[email protected]> Thu, 08 Jan 2004 21:42:15 +0100
Newsgroups gmane.ietf.idwg
Organization France Telecom R et D
Message-ID <[email protected]>
Tthe draft should be more explicit on hte hierarchy between manager 
and analyzer

Situation 1 (serial/transfer)
-----------
Imagine 3 boxes, A=analyzer, B=manager/analyzer, C=manager, connected
thus:

Analyzer-A -> (Manager-B / Analyzer-B) -> Manager-C

You should ([even must ?] not have alerts on C whose analyzerid is
Analyzer-A.

Situation 2 (parallelism/duplication)
-----------

Imagine 3 boxes, A=analyzer, B=manager, C=manager, connected thus:

              /---> Manager-B
Analyzer-A -<
              \---> Manager-C

The same alert on Manager-B and Manager C should [must ?] have the 
same analyzerid+alertid.

I believe that with these two constructs we cover any arrangement that 
anybody may want to make.

I'm not sure this has to go in the document, but it would probably 
clear some misunderstanding.


 From Krzysztof Zaraska on Situation 1:
I'd like to know a rationale for this. In Prelude it's a typical 
situation that C sees alerts generated by A. And it's therefore very 
useful to know where the alert actually originated. We were also 
proposing is a "path record" inside the alert, specifying the managers 
the alert has travelled through.

Hervé:
The drawings just clarify that there must be a change of both 
analyzerid and alertid when going through B, at the moment. I'm open 
to discussion, if there is a concensus for a "path-record" attribute 
that would chain all analyzerids.

Hervé
-- 
Hervé Debar             <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61            GSM: +33 (0)6 74 09 09 66
France Télécom R&D                   Fax: +33 (0)2 31 75 93 13
42 rue des Coutures  (--)  BP 6243  (--)  F-14066 Caen Cedex 4