Skip to content

Add ModSecurity audit log collection and libmodsecurity decoding. - #2286

Merged
atomicturtle merged 3 commits into
ossec:mainfrom
atomicturtle:feature/1390-modsecurity-audit
Aug 11, 2026
Merged

Add ModSecurity audit log collection and libmodsecurity decoding.#2286
atomicturtle merged 3 commits into
ossec:mainfrom
atomicturtle:feature/1390-modsecurity-audit

Conversation

@atomicturtle

Copy link
Copy Markdown
Member

Introduce modsec-audit localfile format for serial audit transactions, nginx error-log ModSecurity decoders/rules, and dedicated audit rules so nginx+libmodsecurity deployments are covered beyond Apache error logs (#1390).

Introduce modsec-audit localfile format for serial audit transactions,
nginx error-log ModSecurity decoders/rules, and dedicated audit rules
so nginx+libmodsecurity deployments are covered beyond Apache error logs
(ossec#1390).
Bind -Z--/-H-- handling to the open transaction id, ignore lookalike
markers injected in request bodies, and tighten audit decoders/rules so
Message matches prefer the H section (ossec#1390 security review).
Resolve CHANGELOG.md by keeping both the ossec#1390 ModSecurity entry and
the ossec#462 syscheck_control flag hardening entry from main.
@atomicturtle
atomicturtle merged commit bfdfcd4 into ossec:main Aug 11, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant