Mike,
The original syslog added a colon after "Inbound", syslog-ng does not (not sure why...) but I changed that little bug and excluded Inbound from entering the 'messages' filter, and it's working.
Jose I think this might be something worth including in the distribution config file, as a lot of people I know complain about messages filling up with firewall hits. Just a thought...
The current configuration file aims to be an "exact" match of the syslog configuration shipped by Red Hat. This allow people to replace sysklogd by syslog-ng without loosing the familiar environment (same sources, destinations, and logging statements). Regards, jpo -- José Pedro Oliveira * mailto: jpo@di.uminho.pt * http://gsd.di.uminho.pt/~jpo * * gpg fingerprint = F9B6 8D87 859D 1C94 48F0 84C0 9749 9EB5 91BD 851B *