8 years ago
Syslog Timestamps and RFC's
Syslog issues:
1. Being bound to only the two RFC for syslog is near sighted: syslog / timestamp / formatting should be more flexible.
2. the biggest concern I have is that Syslog should reflect the time stamp of the COLLECTOR'S NIC at the time the syslog packet ARRIVES at the collector....not the syslog / timestamp of the system sending the message : this is especially important with systems where clock settings or NTP are currently failing......alerting is based on the time stamp : if the time stamp says Jan 1st 2001 12:01am becasue the CMOS battery on the unit failed......than we NEVER see those syslog messages due to alerting range.