This doc gives instructions on how to monitor traffic through a smoothwall express installation using Kiwi Syslog daemon for Windows.
http://www.securitydocs.com/library/2900
Hidden in there are the instructions on SSH'ing into your Smoothie to edit /etc/syslog.conf and adding this line:
kern.* @10.0.0.78
[change the 10.0.0.78 to whatever your log machine happens to be]
Then send syslogd a signal to reset itself and read the edited config file:
killall -HUP syslogd
Note: Text editors - Joe is in SmoothWall Express 2 and 3. Jpico was installed on some earlier SmoothWall versions. Or connect w/WinSCP and use it's built in Windows GUI text editor.
tags: syslog, logging, log file, syslogd, kiwi, firewall