> Source: [sk139852](https://support.checkpoint.com/results/sk/sk139852)

# sk139852 - Audit logs from Gaia WebUI are not logged to /var/log/messages

| Property | Value |
|----------|-------|
| Solution ID | sk139852 |
| Date Created | 2018-11-07 |
| Last Modified | 2018-11-11 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |
| OS | Gaia |

## Symptoms

- In R80.x, CLI Audit logs are written to `/var/log/messages`, while WebUI Audit logs are written as  
`xpand[PID]: Configuration changed from localhost by user admin by the service dbset `   
While in R77.30, the Audit logs from WebUI included all the changes made.

## Cause

The logging of xpand was modified according to [sk103127](http://supportcontent.checkpoint.com/solutions?id=sk103127).

Ths can be verified with the following command:

`[Expert@FW01:0]# dbget -arv xpand`  
`xpand:auditlog p`  
`xpand:auditlog:presentation both`  
`xpand:instance`  
` xpand:instance:name`  
` xpand:instance:name:default t`  
**xpand:log_db_bindings off**   
**xpand:log_msg_level user**

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
