Hello, I have spent the last day hacking around with syslog-ng, and thinks is great. I have just one problem that I have not found an answer to in searching google. I am having difficulty getting it to pick up the entries from sshd2. I have sshd2 set up for SyslogFacility AUTH, and get authentication attempts logged in /var/log/secure using the standard logger, but cannot get them picked up by syslog-ng. I have tried some of the various filters that I have found, but still no information shows up. Anyone have this working? syslog-ng version 1.4.17 Mandrake 8.1, 8.2, 9.0, SSH 3.2.2 At this point, just getting it to log local is fine, as I have been able to get logs to be sent using stunnel, but pretty much gutted the configs down to get this working. Thanks go out to all for syslog-ng and for their support. -Wolverine