1. Edit the file /usr/local/etc/syslog-ng/syslog-ng.conf At the bottom of the file, add: filter f_routers { facility(local5); }; log { source(src); filter(f_routers); destination(routers); }; destination routers { file("/var/log/network/$YEAR/$MONTH/$DAY/$HOST-$YEAR-$MONTH-$DAY-$HOUR.log" owner(root) group(root) perm(0644) dir_perm(0755) create_dirs(yes) template("$YEAR $DATE $HOST $MSG\n")); }; 2. Create the directory /var/log/network/ # mkdir /var/log/network/ 3. Restart syslog-ng: # /usr/local/etc/rc.d/syslog-ng restart 4. See if messages are starting to appear under /var/log/network/2009/02/21/...