Summary

  • RFC 3014 created a local log so an application could recover the contents of an SNMP Trap or Inform that it might not have received over the notification path.
  • The fallback was not an archive of truth: filters, access rules, capacity, age-out, resource pressure, restart epochs and other managers could remove evidence before it was read.
  • Logged and discarded counters, per-log indexes and sysUpTime discontinuities made some losses visible, but could not reconstruct excluded or deleted records.

SNMP Notifications were designed to move management information without waiting for a manager to ask. A device could emit a Trap; an Inform could add acknowledgement and retry. Neither made the path immortal. Retransmission could stop before delivery, the receiver could be unavailable, or a collector could discover the gap only after the transient condition had passed.

RFC 3014, published as a Proposed Standard in November 2000, answered with a local Notification Log MIB. The log was a hedge against lost Traps or Informs. A management application could poll it, resume from the last entry it had collected and reconstruct the Notification PDU from the retained variable bindings.

The apparently simple move changed the evidence architecture. A notification no longer had only one route from originator to receiver. It could also leave a local record that a later reader might retrieve. The asynchronous path and the durable-looking path became two witnesses to one management act.

RFC 3014 refused to pretend that the second witness was complete. Its configuration section controlled what could enter and how much could remain. Its statistics counted entries logged and discarded. Its log held the surviving notifications. The standard therefore described not just memory, but the policy and scarcity surrounding memory.

Admission came first. A named log referred to a filter in the SNMP Notification MIB. An entry appeared only after the Notification passed that filter and any applicable access control. The specification's example created a log that admitted only linkUp and linkDown. Silence elsewhere in that log was not evidence that other Notifications had not occurred; they were outside the selected view.

Security made the view more specific. A named log retained the security credentials of its creator. For a locally generated Notification, the system had to apply the same access check used by a Notification Originator before placing protected objects in that log. A device with fewer resources could expose only the default, null-named log, which carried no implicit creator credentials for admission.

That distinction prevented one user's log from becoming an accidental channel for objects that user could not read. It also meant two authorised observers could receive different histories from the same box. Completeness was never a property of “the log” in the abstract. It was relative to a log name, filter, creator credentials, engine and management context.

The source context mattered because several SNMP engines could operate independently and each could expose several named management contexts. RFC 3014 stored the originating engine identifier and context. A linkDown without those coordinates was not a complete statement about which managed world had changed.

Capacity then imposed a second boundary. nlmConfigGlobalEntryLimit limited all named logs together. nlmConfigLogEntryLimit limited one log. nlmConfigGlobalAgeOut set the number of minutes an entry should remain before automatic removal. Zero could mean no configured limit or no age-out, but it did not create infinite memory.

The standard said so directly: a particular limit did not guarantee that much data could be held. Implementation resources still governed reality. If adding an entry exceeded the global limit or available resources, the oldest entry in any log could be removed. If a named log exceeded its own limit, its oldest entry could give way.

The global limit had priority over age and per-log promises. If a manager lowered it while entries existed, the system had to discard the oldest records until the new limit was satisfied—even if those records were younger than the age-out value and their individual logs remained below their own limits.

This was more than cache mechanics. It defined who could shorten another observer's evidence window. RFC 3014 warned that multiple applications setting shared limits to different values could damage the reliability and completeness seen by each other. One application could delete Notifications before another had a chance to see them. The document named the possibility as a denial-of-service attack and left countermeasures for further study.

The log intended to rescue evidence from an unreliable delivery path therefore acquired its own control-plane attack surface. A Trap could be lost in transit. A retained copy could be excluded by a filter. An admitted row could be evicted by capacity. A still-young row could disappear after a new global setting. The device could restart. Each failure left a different residue.

RFC 3014 provided counters precisely because the residues mattered. Global statistics separated Notifications logged from Notifications discarded. Per-log statistics did the same for each named log. A rising discarded count told the operator that the retained history was losing entries because of resource or capacity pressure.

The counter was not the missing record. It could establish that loss occurred within a counter epoch, but not restore the erased Notification identifier, variable bindings or operational meaning. If ten entries were discarded, the number ten did not reveal whether they were routine link flaps, a fan failure or the only warning before a service interruption.

Polling needed an epoch as well. Each retained row received a monotonically increasing index within its named log. A collector could remember the highest index retrieved and start from there on the next poll. It also had to inspect sysUpTime for a discontinuity that might have reset the index and lost entries.

Index continuity answered a narrow question: did the collector advance through the retained sequence in the current management-system epoch? It did not prove that every generated Notification passed the filter, survived access control, fit available resources or remained until the poll. A gap could expose deletion; the absence of a gap could not expose what was never admitted.

Initialization made the boundary visible. Whether rows survived a management-system restart was implementation-specific; the RFC said one would generally expect that they did not. If an implementation preserved them, timestamps based on the restarted sysUpTime became ambiguous, so pre-restart entries had to expose nlmLogTime as zero. The row could survive while its original relative clock did not.

The log also stored a local date and time only when the system had that capability. A calendar timestamp, a relative uptime and an increasing index were different coordinates. None alone created a trustworthy chronology across restarts, clock changes and multiple engines.

For a retained entry, the model was careful about representation. Each variable binding was stored with an index and a value object appropriate to its SNMP data type. An application could reconstruct the Notification PDU. That was a meaningful receipt: these typed fields were present in the logged message.

It was not proof that the physical or logical condition behind the message was true. An agent might detect incorrectly. A counter might already have wrapped or reset. A remote Notification might be unauthenticated or interpreted under the wrong context. Message reconstruction preserved a claim; it did not promote the claim into the world it described.

The distinction also bounded human action. A collector reading a retained linkDown entry could prove readback of that row. It still could not prove that an operator saw it, correlated the correct interface, opened an incident, authorised a change, restored service or measured the user's result.

The surrounding SNMP framework evolved. RFC 1905 supplied the SNMPv2 protocol operations and InformRequest context. RFC 2573 and RFC 2575 described applications and view-based access control used by RFC 3014; RFC 3413 and RFC 3415 later replaced those framework documents. This lineage changed the surrounding modules, not the evidentiary rule that admission and readback require their own receipts.

Later specifications treated the Notification Log as reusable infrastructure. The Alarm MIB in RFC 3877 could point from alarm history toward an applicable Notification Log row. The SYSLOG-MSG-MIB in RFC 5676 used the generic mechanism to represent syslog messages in SNMP. Those references show architectural reuse; they do not establish deployment, completeness or successful incident response.

Lu Heng's minimum-initial-specification lens explains the strength of the original design. RFC 3014 standardised a small set of common objects—configuration, statistics, source coordinates, indexes and typed values—without declaring one universal retention budget. Operators and implementations kept local resource decisions.

That freedom carried a price. A retention number was a local promise whose execution had to be observed. Running-code primacy asks whether the filter was installed, the row was admitted, the capacity remained unchanged, the counter epoch was continuous and the collector actually read the entry. The MIB definition alone proved none of those facts in a named device.

Reality Layers supplies the final discipline. The event, the Notification, the admitted row, the retained row, the collector's read, the analyst's interpretation, the authorised action and the service result were related but not interchangeable. The log was an evidence system inside the operational system, not a transparent copy of reality.

RFC 3014's most durable contribution was therefore not “store the alert.” It was the explicit admission that backup evidence has filters, owners, quotas and epochs of its own. A lost Notification could be found in the log. A lost log entry could sometimes be inferred from counters or discontinuity. Beyond that boundary, honest systems had to say what they no longer knew.

Sources