Network Working Group S. Chisholm
Request for Comments: 5674 Nortel
Category: Standards Track R. Gerhards
Adiscon GmbH
October 2009
Alarms in Syslog
Chisholm & Gerhards Standards Track [Page 1]
RFC 5674 Alarms in Syslog October 2009
Table of Contents
1. Introduction
In addition to sending out alarm information asynchronously via protocols such as the Simple Network Management Protocol (SNMP) or the Network Configuration Protocol (Netconf), many implementations also log alarms via syslog. This memo defines a set of SD-PARAMs to support logging and defines a mapping of syslog severity to the severity of the alarm.
2. Severity Mapping
The Alarm MIB [RFC3877] defines ITU perceived severities; it is useful to be able to relate these to the syslog message fields, particularly in the case where alarms are being logged. This memo describes the representation of ITU perceived severities in appropriate syslog fields, which are described in [RFC5424]. Syslog offers both a so-called SEVERITY as well as STRUCTURED-DATA. Due to constraints in syslog, there is no one-to-one mapping possible for SEVERITY. A STRUCTURED-DATA element is defined in this document to allow inclusion of the unmodified ITU perceived severity.
Chisholm & Gerhards Standards Track [Page 2]
RFC 5674 Alarms in Syslog October 2009
Syslog supports Severity values different from ITU perceived severities. These are defined in Section 6.2.1 of [RFC5424]. The mapping shown in Table 1 below SHOULD be used to map ITU perceived severities to syslog severities.
3. Alarm STRUCTURED-DATA Elements
STRUCTURED-DATA allows the inclusion of any structured information into a syslog message. The following are defined in this document to support the structuring of alarm information.
3.1. resource
If the "alarm" SD-ID is included, the "resource" SD-PARAM MUST be included. This item uniquely identifies the resource under alarm within the scope of a network element.
Chisholm & Gerhards Standards Track [Page 3]
RFC 5674 Alarms in Syslog October 2009 3.2. probableCauseIf the "alarm" SD-ID is included, the "probableCause" SD-PARAM MUST be included. This parameter is the mnemonic associated with the IANAItuProbableCause object defined within [RFC3877] and any subsequent extensions defined by IANA. For example, IANAItuProbableCause defines a transmission failure to a probable cause of 'transmissionError (10)'. The value of the parameter in this case would be 'transmissionError'.
3.3. perceivedSeverity
If the "alarm" SD-ID is included, the "perceivedSeverity" SD-PARAM MUST be included. Similar to the definition of perceived severity in [X.736] and [RFC3877], this object can take the following values:
3.4. eventType
If the "alarm" SD-ID is included, the "eventType" SD-PARAM SHOULD be included. This parameter is the mnemonic associated with the IANAItuEventType object defined within [RFC3877] and any subsequent extensions defined by IANA. For example, IANAItuEventType defines an environmental alarm to an event type of 'environmentalAlarm (6)'. The value of the parameter in this case would be 'environmentalAlarm'.
3.5. trendIndication
If the "alarm" SD-ID is included, the "trendIndication" SD-PARAM SHOULD be included. Similar to the definition of perceived severity in [X.733] and [RFC3877], this object can take the following values: o moreSevere
Chisholm & Gerhards Standards Track [Page 4]
RFC 5674 Alarms in Syslog October 2009
o noChange
3.6. resourceURI
If the "alarm" SD-ID is included, the "resourceURI" SD-PARAM SHOULD be included. This item uniquely identifies the resource under alarm.
4. Examples
Example 1 - Mandatory Alarm Information
Chisholm & Gerhards Standards Track [Page 5]
RFC 5674 Alarms in Syslog October 2009
<165>1 2004-11-10T20:15:15.003Z mymachine.example.com evntslog - ID48 [alarm resource="interface 42" probableCause="unauthorizedAccessAttempt" perceivedSeverity="major" eventType="communicationsAlarm" resourceURI="snmp://example.com//1.3.6.1.2.1.2.2.1.1.42"]
5. Security Considerations
In addition to the general syslog security considerations discussed in [RFC5424], the information contained with alarms may provide hackers with helpful information about parts of the system currently experiencing stress as well as general information about the system, such as inventory.
6. IANA Considerations
IANA registered the syslog Structured Data ID values and PARAM-NAMEs shown below:
perceivedSeverity MANDATORY
eventType OPTIONAL
trendIndication OPTIONAL
resourceURI OPTIONAL
7. Acknowledgments
Thanks to members of the Syslog and OPSAWG work group who contributed to this specification. We'd also like to thank Juergen Schoenwaelder, Dave Harrington, Wes Hardaker, and Randy Presuhn for their reviews.
Chisholm & Gerhards Standards Track [Page 6]
RFC 5674 Alarms in Syslog October 2009 8. References 8.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
8.2. Informative References
[X.733] ITU-T, "Information Technology - Open Systems