Re: [netmod] Syslog YANG Model Presentation

Chris Lonvick <lonvick@gmail.com> Thu, 31 July 2014 18:36 UTC

Return-Path: <lonvick@gmail.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF5A51A0271 for <netmod@ietfa.amsl.com>; Thu, 31 Jul 2014 11:36:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rIfdI9XkPLcP for <netmod@ietfa.amsl.com>; Thu, 31 Jul 2014 11:36:14 -0700 (PDT)
Received: from mail-vc0-x22b.google.com (mail-vc0-x22b.google.com [IPv6:2607:f8b0:400c:c03::22b]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 389A71A0164 for <netmod@ietf.org>; Thu, 31 Jul 2014 11:36:14 -0700 (PDT)
Received: by mail-vc0-f171.google.com with SMTP id hq11so4946801vcb.30 for <netmod@ietf.org>; Thu, 31 Jul 2014 11:36:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=HFM9y9HxPjsCycxi0z2qAlqIMmIcNanOHyUGqBGiQBs=; b=Ay/TIQSIX9QpURUYW5zHiXnJ1QqNxQir290ZJ9EpqgqR9rxZwJ2rcM7612dXs5ABFW 90Lcv90u4Jq0isrSkRBJJZlX7H9JsbaMFOhVcVAdIzubjoYRUC4xAXvFM/H9n6j59ThD 9fOdbZaDIOWw7tVzyeq0gYtnmVqA07ODdveNGRFz/2fkAWWPHuVEKDjlEdJ3x0Megmxq 65VrSS4YiA/zmX/m76cxaIAOayKE0InwMntLp3ZbCywwuZlNm/7ljj9tNi/Dz0Qk1wVG SJXEThV7XtmyJ8O32AgRsLbed+aemMavSOw15tr24qgoZf6ylMZxr0ETaPnzvb6ih5jB /g3Q==
MIME-Version: 1.0
X-Received: by 10.220.195.67 with SMTP id eb3mr49189vcb.30.1406831773256; Thu, 31 Jul 2014 11:36:13 -0700 (PDT)
Received: by 10.52.231.5 with HTTP; Thu, 31 Jul 2014 11:36:13 -0700 (PDT)
In-Reply-To: <CFFFB9A8.4EE6%jeffrey.k.lange@ge.com>
References: <CFF2F9DA.8B4CA%cwildes@cisco.com> <20140722150553.GB12083@elstar.local> <53CEA093.2070000@cisco.com> <20140730145856.GL29365@pfrc> <53D90D95.5090001@cisco.com> <CFFFB9A8.4EE6%jeffrey.k.lange@ge.com>
Date: Thu, 31 Jul 2014 11:36:13 -0700
Message-ID: <CAPhuMXwZapSr8nEXbzz33R4Ck1FvVkCZN_NhJXqN8pwxenpS-w@mail.gmail.com>
From: Chris Lonvick <lonvick@gmail.com>
To: "Lange, Jeffrey K (GE Energy Management)" <jeffrey.K.lange@ge.com>
Content-Type: multipart/alternative; boundary="089e0158b0a81a946704ff818ca5"
Archived-At: http://mailarchive.ietf.org/arch/msg/netmod/BhIu1_-WzlSkrX0Gw20bs3_YRGo
X-Mailman-Approved-At: Thu, 31 Jul 2014 13:13:55 -0700
Cc: Kiran Agrahara Sreenivasa <kkoushik@brocade.com>, "rgerhards@hq.adiscon.com" <rgerhards@hq.adiscon.com>, "netmod@ietf.org" <netmod@ietf.org>
Subject: Re: [netmod] Syslog YANG Model Presentation
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 31 Jul 2014 20:06:54 -0000

Hi,
The very brief background:
- the syslog WG was chartered under the Security Area to secure the protocol
- the BEEP work never took off so we rechartered and found that we needed
to make changes to the protocol itself
- in making the changes, Rainer Gerhards proposed structured data and the
WG liked that
- 5424 makes use of structured data but there are few implementations that
strictly adhere to the changes made to the packet header

On the other hand, everyone likes structured data and I've seen it used in
many places.  As far as I know, there have been no efforts to standardize
structured data but people are using it in many places because it is very
versatile and efficient, and it gets the job done.  :-)

I've been working (off and on and hopefully more 'on' soon) on an ID that
explains how non-standardized messages have been conveyed in
IETF-documented protocols.  It will need a couple of more revisions before
it's ready for consideration for publication but you may get some ideas
from it.
  https://datatracker.ietf.org/doc/draft-lonvick-private-tax/?include_text=1

Best regards,
Chris


On Thu, Jul 31, 2014 at 6:19 AM, Lange, Jeffrey K (GE Energy Management) <
jeffrey.K.lange@ge.com> wrote:

> Benoit,
>   We (GE MDS) support 5424/5425/5426 structured messages on our products
> (with vendor specific structured-data).
>
> -Jeff Lange
>
>
>
> From: Benoit Claise <bclaise@cisco.com<mailto:bclaise@cisco.com>>
> Date: Wednesday, July 30, 2014 at 11:21 AM
> To: Jeffrey Haas <jhaas@pfrc.org<mailto:jhaas@pfrc.org>>
> Cc: "lonvick@gmail.com<mailto:lonvick@gmail.com>" <lonvick@gmail.com
> <mailto:lonvick@gmail.com>>, Kiran Agrahara Sreenivasa
> <kkoushik@Brocade.com<mailto:kkoushik@Brocade.com>>, "netmod@ietf.org
> <mailto:netmod@ietf.org>" <netmod@ietf.org<mailto:netmod@ietf.org>>, "
> rgerhards@hq.adiscon.com<mailto:rgerhards@hq.adiscon.com>" <
> rgerhards@hq.adiscon.com<mailto:rgerhards@hq.adiscon.com>>
> Subject: Re: [netmod] Syslog YANG Model Presentation
>
> Jeff,
>
> Thanks.
> So I guess we need to support RFC 5424, RFC 5425, and RFC 5426
> configuration in the YANG model, right?
> You use only vendor specific STRUCTURED-DATA? Because I don't see many in
> the IANA registry<
> http://www.iana.org/assignments/syslog-parameters/syslog-parameters.xhtml#syslog-parameters-4>,
> and http://tools.ietf.org/html/rfc5424#section-9.2 requests IANA
> registration.
>
> If my memory serves me well (I copied a couple of old timers), the
> STRUCTURED-DATA goal was to standardize the syslog message content in the
> industry, but that did not happen.
>
> Regards, Benoit
>
> Benoit,
>
> On Tue, Jul 22, 2014 at 01:34:11PM -0400, Benoit Claise wrote:
>
>
> PS: I think you should also refer to the standards-track version of
>     SYSLOG (RFC 5424) in the references and perhaps filters should
>     also be able to operate on structured content.
>
>
> Is RFC 5424 actually deployed?
>
>
> Juniper has supported it for years.
>
> -- Jeff
> .
>
>
>
>