thanks muungwana
odd thing happening here, left firewall turned off then entered in terminal as root.......... echo "" > /var/log/syslog
imediatley entered cat /var/log/syslog expecting to find syslog empty. but no pages of lines (not sure of meanings)
turned firewall back on followed your list of commands, there are maybe 100 lines of output so I repeated
echo "" > /var/log/syslog
cat /var/log/syslog
then immediatley cat /var/log/syslog again and got the following
[root@localhost laurie]# echo " " >/var/log/syslog
[root@localhost laurie]# cat /var/log/syslog
[root@localhost laurie]# cat /var/log/syslog
Jun 26 11:35:13 localhost last message repeated 2 times
Jun 26 11:35:17 localhost psad: scan detected: 127.0.0.1 -> 127.0.0.1 udp: [512] tcp pkts: 2 udp pkts: 2 DL: 4
Jun 26 11:35:17 localhost sendmail[17537]: p5Q3ZHUl017537: from=root, size=1260, class=0, nrcpts=1, msgid=<201106260335.p5Q3ZHUl017537@localhost.localdomain>, relay=root@localhost
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=17072 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=32792 RES=0x00 SYN URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=32768 RES=0x00 ACK SYN URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=17073 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=513 RES=0x00 ACK URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=48556 DF PROTO=TCP SPT=58198 DPT=113 WINDOW=32792 RES=0x00 SYN URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=113 DPT=58198 WINDOW=0 RES=0x00 ACK RST URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=141 TOS=0x00 PREC=0x00 TTL=64 ID=36161 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=512 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=17074 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=513 RES=0x00 ACK URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=80 TOS=0x00 PREC=0x00 TTL=64 ID=17075 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=513 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=36162 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=512 RES=0x00 ACK URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=271 TOS=0x00 PREC=0x00 TTL=64 ID=36163 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=512 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=134 TOS=0x00 PREC=0x00 TTL=64 ID=17076 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=105 TOS=0x00 PREC=0x00 TTL=64 ID=36164 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=512 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=96 TOS=0x00 PREC=0x00 TTL=64 ID=17077 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=158 TOS=0x00 PREC=0x00 TTL=64 ID=36165 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=512 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:17 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=1624 TOS=0x00 PREC=0x00 TTL=64 ID=17078 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:17 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=36166 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=55 TOS=0x00 PREC=0x00 TTL=64 ID=17079 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=36167 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost sendmail[17538]: p5Q3ZHrx017538: from=<root@localhost.localdomain>, size=1528, class=0, nrcpts=1, msgid=<201106260335.p5Q3ZHUl017537@localhost.localdomain>, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1]
Jun 26 11:35:18 localhost sendmail[17537]: p5Q3ZHUl017537: to=root@localhost, ctladdr=root (0/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31260, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (p5Q3ZHrx017538 Message accepted for delivery)
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=108 TOS=0x00 PREC=0x00 TTL=64 ID=36168 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=58 TOS=0x00 PREC=0x00 TTL=64 ID=17080 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=104 TOS=0x00 PREC=0x00 TTL=64 ID=36169 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK PSH URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=36170 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK FIN URGP=0
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=17081 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK FIN URGP=0
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=36170 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK FIN URGP=0
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=17081 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK FIN URGP=0
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=36170 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK FIN URGP=0
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=17081 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK FIN URGP=0
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=36171 DF PROTO=TCP SPT=25 DPT=50111 WINDOW=770 RES=0x00 ACK URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=17082 DF PROTO=TCP SPT=50111 DPT=25 WINDOW=530 RES=0x00 ACK URGP=0
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=62 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=56053 DPT=512 LEN=42
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost klogd: IN= OUT=lo SRC=127.0.0.1 DST=127.0.0.1 LEN=90 TOS=0x00 PREC=0xC0 TTL=64 ID=36091 PROTO=ICMP TYPE=3 CODE=3 [SRC=127.0.0.1 DST=127.0.0.1 LEN=62 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=56053 DPT=512 LEN=42 ]
Jun 26 11:35:18 localhost last message repeated 2 times
Jun 26 11:35:18 localhost sendmail[17539]: p5Q3ZHrx017538: to=<root@localhost.localdomain>, ctladdr=<root@localhost.localdomain> (0/0), delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31761, dsn=2.0.0, stat=Sent
[root@localhost laurie]#
If I follow your instructions I get much more output
there seems to be a constant activity behind the scenes
Laurie