Skip to content

Add modsecurity log vars#374

Open
meirdev wants to merge 3 commits intoowasp-modsecurity:masterfrom
meirdev:add-modsecurity-log-vars
Open

Add modsecurity log vars#374
meirdev wants to merge 3 commits intoowasp-modsecurity:masterfrom
meirdev:add-modsecurity-log-vars

Conversation

@meirdev
Copy link
Copy Markdown

@meirdev meirdev commented Apr 22, 2026

what

Add two variables to the module: $modsecurity_intervention and $modsecurity_triggered_rules.

  • $modsecurity_intervention: set to 1 if ModSecurity triggered a disruptive intervention.
  • $modsecurity_triggered_rules: a comma-separated list of matched rule IDs.

why

NGINX logs already contain a lot of useful data, but they don't include ModSecurity events. That makes it hard to correlate what you see in NGINX logs with what shows up in ModSecurity audit logs.

If you're sending logs to an "append-only" databsae, theres no easy way to correlate the two later. And trying to sync them beforehand usually means building a complex buffering and matching system.

meirdev added 3 commits April 22, 2026 00:23
Adds two nginx variables usable in log_format / access_log:
- $modsecurity_intervention: "1" if ModSecurity intervened, "0" otherwise
- $modsecurity_triggered_rules: comma-separated IDs of all matched rules
@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant