Modsec v3 severity not logged properly

Christian Varas <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <[email protected]>
Hello,

I’m having some issues with modsecurity 3 nginx connector,  in the rules, the severity is properly set, like “CRITICAL”, "WARNING", "NOTICE", but when is logged in the audit logs, the severity comes with the id and not with the "name".

I’m expecting: “severity”: “CRITICAL”
I’m getting: “ severity”: “2”

Does anyone know how to solve this ?, maybe I’m missing an option in the config file...


{"transaction":{"client_ip":"192.168.104.1","time_stamp":"Tue Aug 14 16:17:41 2018","server_id":"43207054df5b4474bc005b6ead41801dd55b95f8","client_port":56856,"host_ip":"192.168.104.1","host_port":80,"id":"153427786186.625665","request":{"method":"GET","http_version":1.1,"uri":"/favicon.ico","body":"","headers":{"Host":"www.test.com","Connection":"keep-alive","Pragma":"no-cache","Cache-Control":"no-cache","User-Agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36","Cookie":"_ga=GA1.2.822423841.1533594347; __utmz=129959823.1533594349.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=(not%20provided); _gid=GA1.2.1519461480.1534272702; __utma=129959823.822423841.1533594347.1533854693.1534272702.5; __utmc=129959823","Accept":"image/webp,image/apng,image/*,*/*;q=0.8","Referer":"http://www.test.com/?s=sdsd%3Cscript%3Ealert();%3C/S","Accept-Encoding":"gzip, deflate","Accept-Language":"en-US,en;q=0.9,es;q=0.8"}},"response":{"http_code":403},"producer":{"modsecurity":"ModSecurity v3.0.2 (Linux)","connector":"ModSecurity-nginx v1.0.0","secrules_engine":"Enabled","components":["OWASP_CRS/3.0.2\""]},"messages":[{"message":"XSS Filter - Category 1: Script Tag Vector","details":{"match":"Matched \"Operator `Rx' with parameter `(?i)([<<]script[^>>]*[>>][\\s\\S]*?)' against variable `REQUEST_HEADERS:Referer' (Value: `http://www.test.com/?s=sdsd%3Cscript%3Ealert();%3C/S' )","reference":"o30,8o30,8v303,55t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls","ruleId":"941110","file":"/opt/waf/nginx/etc/modsec_rules/www.test.com/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf","lineNumber":"63","data":"Matched Data: <script> found within REQUEST_HEADERS:Referer: http://www.test.com/?s=sdsd%3Cscript%3Ealert();%3C/S","severity":"2","ver":"OWASP_CRS/3.0.0","rev":"2","tags":["application-multi","language-multi","platform-multi","attack-xss","OWASP_CRS/WEB_ATTACK/XSS","WASCTC/WASC-8","WASCTC/WASC-22","OWASP_TOP_10/A3","OWASP_AppSensor/IE1","CAPEC-242"],"maturity":"4","accuracy":"9"}}]}}

Cheers.
Chris.

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE+lVmIc22zrKXDiqOjFiNVamI5zQFAlt3KAMACgkQjFiNVamI
5zRy7w//bG1z7gzJujKTaLMUbeyX8K7YPmL+fOgvGGYV50NLCv1yBABLR/h87YvE
KJRF6rhkztPZ8yCXn+BXi7RzDdfU8xDgiOj5wAh+bpqVsGPlHnSQxVw2iXrF0lE4
ux/sX5XMUgUSw4x7N3fs+gF+UrX9krpaEenlNtzIteV5oRcO06z6FD+Rtke1xPYw
cgjIzCT6krHm5x8UPMNyHu2Nt4DT/moF5t7PZHefhlMOgb7hzWu6NxViRL2uHw+K
5VG8RGELUzgDugz1lGnuMT6DP8lAjdWx6wZexYoxxf+tSQMrVLpGQV1LcoDUZsCB
F0wqZfydj1HXM6MJKh3ZNKaK4rVOdsZCmSfAxehCQuVsplqLUlHge4h4q28pTiQK
YFNFsNfpXIAJzFBPVT+1Lil6VzJ8T5Fd8P9mtMW+2pf9e+PjfB9b6R2VwJjj8lpE
E+xaIFjy2OmuPiUw6pdOMPhpX8IeLYd2i3PjVk7y3HwK/PuY8nJxZU3/lrReu9s0
0hS8Y/7/TRVYip/6LnMRcJqK0F3EXnkNUDkUdTzNX0WjgxF4zjVxTLPCKG5phB8k
Da94a8edwlx0fxWuyKy0oX9wB/KI1H1GEIzj7dOjREwWzrrzojLkwwsL/wdzuLde
x8kjseoiNjXq2hWVx6SbV9eFwO547QxH5SR0RYz5+DINyiZPp8Y=
=oE19
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.