> Source: [sk113897](https://support.checkpoint.com/results/sk/sk113897)

# sk113897 - /var/log/messages file is filled with Audit Logs for Gaia Clish commands

| Property | Value |
|----------|-------|
| Solution ID | sk113897 |
| Date Created | 2016-10-13 |
| Last Modified | 2019-12-12 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.20 |
| OS | Gaia |

## Symptoms

- */var/log/messages* file is filled with Audit Logs for Gaia Clish commands:
`
clish[`*PID* `]: user logged from admin`  
`
clish[`*PID* `]: cmd by admin: Start executing : xxx (cmd md5: ...)`  
`
clish[`*PID* `]: cmd by admin: Processing : xxx (cmd md5: ...)`  
`
clish[`*PID*`]: cmd by admin: Start executing : exit (cmd md5: ...)
`

## Cause

By default, Audit Logs for Gaia Clish commands are written by the `clishd` and `xpand` daemons with `local0` priority to the `/var/log/messages` file.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
