Greetings as im in the process of doing numorous things on my system, one thing has been bothering me for quiet a while, that is having fw event records in /var/log/messages personally i think that those should go into their own fw log /var/log/firewall.log so i tried to do the following: 1- in /etc/sysconfig/SuSEFirewall2 I edited the FW_LOG parameter to add SuSE_FW 2- in both /etc/syslog-ng/syslog-ng.conf and /etc/syslog-ng/syslog- ng.conf.in I edited the following to such filter f_iptables { facility(kern) and match("SuSE_FW"); }; & destination firewall { file("/var/log/firewall.log"); }; log { source(src); filter(f_iptables); destination(firewall); }; flags(final); }; 3- I edited /etc/syslog.conf to the following: kern;mail.none;news.none;authpriv;auth.none -/var/log/messages & kern.warn -/var/log/kern.log kern.notice;kern.* /var/log/firewall.log now with the current configuration and due to the third modification list above, i can get the firewall to log events under /var/log/firewall.log but i do not get the common logs anymore in /var/log/messages usch as users sessions etc my question is, how am i to modify the syslog.conf to get only the firewall events diverted to the /var/log/firewall.log log? another question is, what is your opinion and best way to get firewall to log directly to mysql? and my last question is, why has suse performed such a basic setup, what are the reasons behind that and will it be intruducing db log support in future releases? -- Regards -RP- ___________________________ If computers were made in heaven, would they be perfect? ___________________________