Hi there, i'm having a little trouble with logcheck here. I'm running a linux firewall-box with iptables here and the "drop's" are logged with a "INPUT-(protocol)-DROP" prefix into a seperate logfile. I setup logcheck only to check this file and report all "INPUT-(protocol)-DROP" entrys. I have added the "INPUT-(protocol)-DROP" lines into logcheck.violations. That just works fine. But now there are sometimes some "drop's" originating from the internal lan. So i added an entry like "SRC=192.168.1." in logcheck.violations.ignore so that every line containing SRC=192.168.1. should be left out. If i got it right, then a line with INPUT-(protocol)-DROP and NO SRC=192.168.1. should be reported, and a line with INPUT-(protocol)-DROP AND SRC=192.168.1. shouldn't be. But these lines are still reported. Can you tell what i did wrong? thanks in advance, Jan Räther -- Jan Räther Universitaet Hamburg Zentrum für Molekulare Neurobiologie Service-Gruppe EDV Falkenried 94 20251 Hamburg Germany Tel.:040 - 428 - 03 - 6619 Fax.:040 - 428 - 03 - 6621 Q: How many surrealists does it take to change a light bulb? A: Two. One to hold the giraffe and the other to fill the bathtub with brightly colored machine tools.