Both TCP and UDP have risks and limitations. If message loss/spoofing are important to you, TCP is the way to go. (One key exception being logs from PIX firewalls :) Is the log server handling other services as well? Kevin