You can use tcpwrappers to do this. Compile syslog-ng with tcpwrappers turned on and in your hosts.allow file put your network address, then add your chatter box to hosts.deny. Regards, Drew -----Original Message----- From: Jay Davis [mailto:jay_davis@fanniemae.com] Sent: Monday, April 28, 2003 11:01 PM To: syslog-ng@lists.balabit.hu Subject: [syslog-ng]Filter question. If I set up a filter to allow messages from a wide spectrum of systems. (whole subnets) can I block a particular host that is a potential flood device. i.e. allow 10.1.20.* but block 10.1.20.36? -- Jay Davis Cell: 443-253-0469 _______________________________________________ syslog-ng maillist - syslog-ng@lists.balabit.hu https://lists.balabit.hu/mailman/listinfo/syslog-ng Frequently asked questions at http://www.campin.net/syslog-ng/faq.html