[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: draft-ietf-opsec-logging-caps-03




On Jul 3, 2007, at 11:39 PM, Warren Kumari wrote:

One possible concern with rate-limiting syslog / SNMP / whatever is that people will then try and generate non-critical events that cause alerts to be generated in the hope that they can then slip a more nefarious event in and have it also be caught by the rate- limiter.

Possible, but hard to accomplish without inside knowledge (which is certainly a possibility, of course).

What would be great would be, if there were a rate-limiter it would prioritize high severity messages over lower severity ones (whee! QoS for logs!).

How about multiple rate-limiters for each individual log-type, as well as for each severity/informational level?

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@cisco.com> // 408.527.6376 voice

       Culture eats strategy for breakfast.

               -- Ford Motor Company