Skip to content

audit log H appears truncated #3301

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
ag-luca opened this issue Nov 13, 2024 · 3 comments
Closed

audit log H appears truncated #3301

ag-luca opened this issue Nov 13, 2024 · 3 comments
Labels
3.x Related to ModSecurity version 3.x

Comments

@ag-luca
Copy link

ag-luca commented Nov 13, 2024

Hi,

I'm not sure if this is a bug, but I've been looking for hours and I can't find similar errors, in my fresh installation of modsecurity on nginx it seems that logs that part H is truncated. Missing fields: Action, Stopwatch, Stopwatch2, Response-Body-Transformed, Producer, Server, Engine-Mode (compared to modsecurity with apache logs)

Current config:
Ubuntu 22.04.5 LTS, nginx/1.18.0, modsecurity-v3.0.13, modsecurity-nginx-v1.0.3, crs 4.8.0

nginx log part H
modsec_audit

example expected result
expected_res

thank you

@ag-luca ag-luca added the 3.x Related to ModSecurity version 3.x label Nov 13, 2024
@airween
Copy link
Member

airween commented Nov 14, 2024

Hi @ag-luca,

the second format is used by only Apache with mod_security2 module. libmodsecurity3 does not contain that format at all.

@ag-luca
Copy link
Author

ag-luca commented Nov 14, 2024

Hi @ag-luca,

the second format is used by only Apache with mod_security2 module. libmodsecurity3 does not contain that format at all.

Thank you very much @airween

@ag-luca
Copy link
Author

ag-luca commented Nov 14, 2024

libmodsecurity3 does not contain the same log format as modsecurity2 part H. Thanks @airween

@ag-luca ag-luca closed this as completed Nov 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
3.x Related to ModSecurity version 3.x
Projects
None yet
Development

No branches or pull requests

2 participants