Summary
- RFC 1404 proposed common metrics, a common interchange format and common reports for independently operated networks; it did not propose a central authority over their monitoring.
- A portable value carried the actual polling period, aggregation period, time, resource identity, total-or-peak class and poll delta. Those fields bounded what another operator could compare.
- RFC 1857 later put the loss plainly: aggregation reduces stored data and also reduces available information. A mean or maximum could travel, but it could not become the raw sample history again.
The graph was the last record, not the first event
Imagine two network operations centres trying to compare load. Both display a bar labelled “peak.” One collector sampled every minute; the other every ten minutes. One retained the largest one-minute rate inside an hour; the other calculated a maximum from already averaged blocks. The bars may share a unit and still describe different events.
RFC 1404, published as Informational in January 1993, began from that coordination problem. It proposed a model for operational statistics that different NOCs could share with little new development or continuing effort. The model covered a minimal set of metrics, a common storage format and methods for daily, weekly, monthly and yearly reports. Existing tools could be adapted through conversion filters; public-domain implementations were encouraged.
This was a deliberately small common layer. It did not require every network to adopt one collector, one database or one definition of its business. It tried to make the evidence crossing the boundary explicit enough to interpret.
That required following the value backward. A report came from an aggregate. An aggregate came from samples. A sample came from a counter or state retrieved from a particular device. The object had its own semantics. The collector had a schedule. The resource might not be identical to the physical interface that happened to supply the measurement. Every transition could preserve, transform or discard information.
A MIB name did not make an observation
The measurement list drew on objects defined in MIB-II, RFC 1213: input and output octets, unicast and non-unicast packets, discards, interface operational status, forwarded datagrams and system uptime. Those definitions gave operators a common name and type for a counter or state.
They did not say what a particular network had observed.
SNMP, RFC 1157, supplied simple request and response operations for management information. A successful response could establish that an agent returned a value at a poll. It could not, by itself, prove that the interface was the intended resource, that no counter reset occurred, that the interval was what the configuration promised, or that a later file preserved the value faithfully.
RFC 1404 also classified desired statistics by collection difficulty. Some lived in the standard MIB, some in enterprise MIBs, some required high-resolution polling, some were absent from any MIB, some were available only per node, and some could not be obtained with SNMP. The list admitted a useful negative fact: agreeing that a measurement mattered did not make the measurement available.
The interval belonged to the value
For interface octets and unicast packets, RFC 1404 recommended an initial polling interval no longer than one minute. If a system could not meet that rate, it should use an exact multiple of sixty seconds and store the actual interval. Other variables could be polled less often, again on an exact multiple of a minute.
The insistence on “actual” matters. A configuration may say sixty seconds while scheduling delay, device load or loss creates a different elapsed period. The common data line therefore included a timestamp and a poll delta. The format did not ask a reader to assume that each adjacent value covered an identical slice of time.
This is where portability stopped being a matter of comma placement. A counter delta without elapsed time cannot yield a bounded rate. A peak without its peak period cannot be compared confidently with another peak. A month of points without the original aggregation period may be visually smooth and evidentially ambiguous.
The resource could survive the interface
RFC 1404 separated the interface that produced raw values from the resource an operator meant to track. A link could move to different hardware or an interface could be reconfigured. If a long-term report followed only the raw interface identifier, the replacement might appear as the death of one series and the birth of another.
Preprocessing could map those interface observations to the continuing resource. This was not cosmetic renaming. It was an assertion of continuity that made a year-long utilization record possible across equipment changes.
The assertion also had limits. Mapping two interfaces to one resource did not prove identical behavior, eliminate a collection gap or turn a replacement event into a seamless physical fact. It preserved the analytical subject under a declared transformation. Another operator needed that device and resource context to know what the series claimed to follow.
A common file carried a compact lineage
The storage model divided context into label, device and data sections. The label identified UTC start and stop times and the associated data file. The device description named the network, router and link, bandwidth and unit, protocol and address, time zone and a tag table. Data rows carried a timestamp, tag, poll delta and delta values.
Each variable was associated with an initial polling period and an aggregation period. Tags distinguished totals from peaks. The record was therefore more than a bag of numbers. It was a small lineage contract: which resource, which clock, which sampling cadence, which transformation and which result class.
That contract made conversion possible without pretending that conversion was neutral. An older local tool could emit the common form through a filter. The common representation made the output parseable elsewhere. Neither fact proved that the source collector was correct, that the mapping was honest or that the receiving NOC used an equivalent local category.
The RFC's treatment of “customer” exposes the boundary. Reports could show offered load by customer, but each installation defined customer locally. The grammar travelled; an important business meaning did not automatically become universal.
Aggregation bought time by selling detail
High-resolution samples accumulate quickly. RFC 1404 proposed progressive aggregation: keep one-minute material briefly, fifteen-minute aggregates for about a day, hourly aggregates for about a month and daily aggregates for about a year. It recommended preserving both averages and maxima.
The 1995 revision, RFC 1857, obsoleted RFC 1404 and refined the interchange grammar. It also stated the tradeoff without euphemism: aggregation reduces the amount of data, but it reduces the available information too. Average values used an arithmetic mean; peak values used a maximum. A peak was relative to a chosen peak period, and changing that period could change the answer.
A maximum preserves one extremum and forgets its surrounding shape. An average preserves a centre and can erase a short overload. Keeping both is better than keeping either alone, but it still does not preserve the original sequence. Once the raw samples have expired, a later investigator cannot derive every smaller-window peak, reconstruct a burst, or test a different aggregation rule.
The graph has not become false. Its authority has narrowed.
Comparable did not mean trusted, identical or consequential
RFC 1404 raised legal, ethical and political questions about sharing operational data. It named integrity, conformity and confidentiality as concerns, and noted that useful comparison required the same measurements and the same polling and aggregation intervals. It did not provide a cryptographic trust system for the files. SNMP's ability to retrieve a value did not secure the later interchange.
The evidence ladder therefore remains long: a MIB object defines a field; an SNMP response returns a value; a collector records a timed sample; preprocessing maps it to a resource; aggregation creates a mean, total or maximum; an interchange file lets another tool parse it; a report supports a bounded comparison; an operator may make a documented decision; a capacity change, repaired incident or customer result needs separate evidence.
No rung inherits the authority of the next. A graph can accurately summarize its inputs while the inputs are incomplete. Two files can conform to the same syntax while local definitions differ. A high peak can justify investigation without proving congestion. A capacity order can be placed without proving that it later improved service.
Sources
- RFC 1404 — A Model for Common Operational Statistics
- RFC Editor record for RFC 1404
- RFC 1857 — A Model for Common Operational Statistics
- RFC 1157 — A Simple Network Management Protocol
- RFC 1213 — MIB-II
- Minimum Initial Specification, Localized Future Decision, and Voluntary Adoption
- On Reality Layers, Symbolic Power, and Why Clarity Feels So Hostile
- Running-Code Primacy
These sources establish document status, specified objects, recommendations and interchange semantics. They do not establish universal deployment, trustworthy collection, a measured incident, a capacity decision or an end-user outcome.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
