Andy Bierman writes:
Anyone one the list with an opinion, please speak up!
Hey, that's me!! ;^)
I do feel that we need more than syslog. In particular, I want
to be able to say "give me all the events from the last 20 minutes
that relate to interface fe-1/2/3.0". So I need to be able to
ship specific fields in addition to the message text. Consider:
<notification>
<time seconds=234532455432345>Oct 18 16:01:37</time>
<tag>RPD_RSVP_NBRUP</tag>
<hostname>farmer-john</hostname>
<process pid=2958>rpd</process>
<data>
<neighbor>10.5.14.2</neighbor>
<interface>fe-1/3/0.0</interface>
</data>
<message>RSVP neighbor 10.5.14.2 up on interface fe-1/3/0.0</message>
</notification>
Yes, I hear you gag on the obnoxious verbosity compared with the
traditional syslog line:
Oct 18 16:01:37 farmer-john rpd[2958]: RPD_RSVP_NBRUP: RSVP neighbor 10.5.14.2 up on interface fe-1/3/0.0