[root at frank-01 ~]# audit2allow -M local < /tmp/avcs -bash: /tmp/avcs: No such file or directory Where to go next. The logs are mailed to "root at localhost" by exim. What and where need to be allowed. Have already done a /sbin/fixfiles relabel. (mislabelled stuff) To allow for future logs? Frank