Syslogd can be configured to receive messages from remote hosts (via UDP). To enable this feature, start syslogd with the -r option. Then add the syslog server to the /etc/syslogd.conf file in the client (use a @host syntax). This is useful to preserve an audit trail even if a cracker does a rm -rf