> Source: [sk173825](https://support.checkpoint.com/results/sk/sk173825)

# sk173825 - After upgrade from R80.10, the security log header sent to the syslog server shows the host name and not the IP address of the machine.

| Property | Value |
|----------|-------|
| Solution ID | sk173825 |
| Date Created | 2021-06-02 |
| Last Modified | 2021-06-03 |
| Technical Level | Advanced |
| Products | Security Management Server, Logging & Status |
| Versions | R81 (EOS), R81 (EOS) |

## Symptoms

- After upgrading from version R80.10, the format of the security log that is sent to the syslog server is changed. The IP Address is replaced by the hostname. See below.

```

e.g.
[R80.10]
May 10 11:48:57 192.168.1.1 httpd2: HTTP login from 172.24.18.108 as admin
May 10 11:48:57 192.168.1.1 xpand[5032]: admin localhost t +webuiparams:logincount:admin 9
May 10 11:48:57 192.168.1.1 xpand[5032]: Configuration changed from localhost by user admin
May 10 11:49:00 192.168.1.1 xpand[5032]: backup_live_get_proc: Unable to open status file
May 10 11:49:00 192.168.1.1 xpand[5032]: failed to read status file

[R80.30]
May 10 11:49:35 HostName httpd2: HTTP login from 172.24.18.108 as admin
May 10 11:49:35 HostName xpand[5393]: admin localhost t +webuiparams:logincount:admin 38
May 10 11:49:35 HostName xpand[5393]: Configuration changed from localhost by user admin
```

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
