Naturally by these questions, I'm not as an Seasoned Veteran of Linux as I am with Winblow$ machines so I'm stumbling a little but I have 5 questions: Syslogs and security; 1. Where are the SYSTEM logs stored? 2. I saw this in my logs today "Jun 5 04:02:29 MYSERVERNAME syslogd 1.4.1: restart." - I didn't restart my computer and if I'm correct, does this mean my system was started? 3. I know what it is on a WinBlow$ machine but I'm not sure on Linux, if a new account is on the system, where is that security event shown/tracked? 4. My Security logs only showed two entries :Jun 5 17:23:14 MYSERVERNAME xinetd[3358]: START: sgi_fam pid=13765 from=<no address> Jun 5 20:19:32 MYSERVERNAME xinetd[3358]: START: sgi_fam pid=14119 from=<no address>", this can't be possible - it appears to have been cleared? Is that possible? 5. How can I prevent my logs from being cleared and/or track when they have been? Thanks in advance. -- /==========The One===========\ "..I don't care your a PhD...put you're hands up, and step away from my keyboard..." -- redhat-list mailing list unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe https://www.redhat.com/mailman/listinfo/redhat-list