> Source: [sk100225](https://support.checkpoint.com/results/sk/sk100225)

# sk100225 - "Configuration changed from localhost by user admin" appears in /var/log/messages file on Gaia OS

| Property | Value |
|----------|-------|
| Solution ID | sk100225 |
| Date Created | 2014-04-10 |
| Last Modified | 2016-01-28 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- The message "`Configuration changed from localhost by user admin`" appears in `/var/log/messages` file even when no one is making any Gaia OS configuration changes.

## Cause

Certain user space daemons (e.g., responsible for IPS Updates, Anti-Virus Update, etc.) will cause the Gaia OS configuration to be saved, which in turn generates this message.

## Solution

No fix is required; the system is functioning as designed.

Note: The message text is planned to be updated in future versions to says that the configuration was changed by the machine (and not by the user).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
