syslog WG Rechartering Discussion
2009-06-01 20:02:38 GMT
Hi Folks, David and I are going to open the discussion about rechartering. Below are some ideas that we've seen on the list that may fit into a charter for a new syslog Working Group. These seem to fit better in the Operations and Management Area than in the Security Area so we are asking the ADs to move the WG to there when we do recharter. We'd like to get the discussion started now on this mailing list and have a WG meeting in Stockholm to discuss rechartering issues. We hope that by having a real meeting, we can draw in more OPS people who are willing to work on these items, and/or to craft additional goals for syslog. Please send your comments in about this and help move syslog forward. Fundamentals - Documenting how a syslog relay is supposed to work. RFC3164 says that a relay MAY change the header information in a syslog message. This needs to be reexamined since syslog-sign mandates that no changes are allowed in the whole syslog message between the sender and the device that validates the detached signatures. - A DHC option for a syslog receiver. Write an ID that standardizes how DHCP should specify a syslog server and associated transport (udp, tls, beep) in a URI format. - The OpSec WG was planning to develop a draft about log event taxonomy (what to log). This work should be compared to the syslog-alarm draft from Sharon and Rainer, which defines categories for the alarm that are fairly consistent with the ALARM-MIB and ITU alarm categories. There is also CEE work that is also trying to define catagories of what to log.(Continue reading)
RSS Feed