Re: Cloud Logging Format
Juergen Schoenwaelder <[email protected]> Wed, 4 Apr 2012 18:19:54 +0200
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Apr 04, 2012 at 08:56:33AM -0700, Gene Golovinsky wrote: > Let me repeat the question I asked at the meeting. From reading the draft, > it was not clear how the new SDEs are added to syslog messages. > Is it reasonable to assume that the originator of a syslog message has the > relevant information? > [Gene Golovinsky] Yes, the originator of the message, the actual logging > entity should be aware of the information populated into the Syslog > message What is a logging entity? RFC 5424 talks about 'originators', 'collectors', and 'relays'. I hear you saying it is the syslog originator. > If not, what does it take to distribute the necessary information to the > originators? Or is the idea that proxies add SDEs while forwarding syslog > messages? > [Gene Golovinsky] Yes again. As a request for service (API call) travels > through processing nodes those nodes add SDs to the message. Each node is > aware of the context and can add appropriate SD. I fail to understand this. Which API call? Who is calling this API? Which nodes add SDs to messages (presumably SYSLOG messages?). Are we now talking relays? > I like to see how this can reasonably implemented and deployed. > [Gene Golovinsky] I am not sure I understand this. It has been actually > implemented and deployed by several vendors in their "cloud" > implementations. Such as? Sorry if I am ignorant. Do typical web servers do this sort of thing or do you have some specific application frameworks in mind? /js -- Juergen Schoenwaelder Jacobs University Bremen gGmbH Phone: +49 421 200 3587 Campus Ring 1, 28759 Bremen, Germany Fax: +49 421 200 3103 <http://www.jacobs-university.de/>