Hi.. I have the following entries *.info;mail.none;cron.none; /var/log/messages in /etc/syslog.conf. And I found that it has these authentication entires Aug 29 10:21:43 watch sshd(pam_unix)[10600]: session opened for user ffff logged in the file /var/log/messages May I know how to get rid of that ? I tried to add authpriv.!alert;authpriv.!crit;authpriv.!err;authpriv.!warn;authpriv.!notice;authpriv.!info;authpriv.!debug; on the same line and restart syslog and no effect. Any help? __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com