From: Steve Grubb <sgrubb@redhat.com>
To: John Dennis <jdennis@redhat.com>
Cc: linux-audit@redhat.com
Subject: Re: comparing record ids in auparse
Date: Wed, 5 Sep 2007 13:17:33 -0400 [thread overview]
Message-ID: <200709051317.34281.sgrubb@redhat.com> (raw)
In-Reply-To: <1189010228.15928.19.camel@junko.usersys.redhat.com>
On Wednesday 05 September 2007 12:37:08 John Dennis wrote:
> On Wed, 2007-09-05 at 12:23 -0400, Steve Grubb wrote:
> > On Wednesday 05 September 2007 12:11:46 John Dennis wrote:
> > > Should two different events from two different hosts be comparable?
> >
> > In a consolidated log, they are not equal. I suppose that should be fixed
> > in the next release.
>
> Right, but the way the cmp operator works is if it's not equal it's
> either less than or greater than,
Yeah, and I want to leave it that way. Its intent is to provide a way to
compare a data type that is not straight forward.
> neither of which is meaningful as a result if they are not from the same
> host, right?
What you seek is a yes/no answer. Are they from the same host? Cause based on
that answer, you may or may not want to compare timestamps.
> At the moment all I can think of is that auparse_timestamp_compare() will
> have to be deprecated and replaced with a different function, unless you
> have a better idea. Suggestions?
It could be incumbent on the programmer to know what's being compared. :)
I think this is a common database programming issue. (auparse is modelled
after database functions.) Suppose you have a POS database. You have sales
information from many stores. If you want to total the sales from a
particular store, you have to select that store within a time range. If you
wanted all sales for a day, you just check timestamps.
IOW, I think the programmer should know what they are trying to do and take
nodes into account. We can easily write a function that takes 2 events and
decides if they are from the same node. That would give you the yes/no
answer.
-Steve
prev parent reply other threads:[~2007-09-05 17:17 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-09-05 16:11 comparing record ids in auparse John Dennis
2007-09-05 16:23 ` Steve Grubb
2007-09-05 16:37 ` John Dennis
2007-09-05 17:17 ` Steve Grubb [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200709051317.34281.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=jdennis@redhat.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.