5 ms·
The `<Data Name="key">value</data>` in there makes me sad. It's better than the `<field name="key" value="value"/>` one of our partners uses at work but still..
by michh 12y ago
The `<Data Name="key">value</data>` in there makes me sad. It's better than the `<field name="key" value="value"/>` one of our partners uses at work but still...
If there's a good reason for it, it's just as much of a good reason XML isn't suitable for what you're trying to do.
- pestaa 12y agoIt's not a deal-breaker, but <key>value</key> would indeed be nicer.
- LoneWolf 12y agoFor a human to read maybe, but for some generic parsing where there are many diferent keys, I would say <data Name="key">value</data> is indeed better, also makes an XSD easier to create, if needed.
- michh 12y agoThat definitely goes towards the "good reason not to use XML" part of what I said, imo ;)
- karlmdavis 12y agoI can understand why they wouldn't have wanted to create an XSD covering all of the possible keys.
- kryptiskt 12y agoFree-form tag names invariably leads to conflicts with previously defined tags that are used for other purposes. I don't see how not wanting an unbounded number of different tags would be antithetical to use of XML.
- windowsworkstoo 12y agoThis is a limitation of the way ETW does structured logging, rather than a design decision in sysmon itself.