轉寄: Welcome to the "mo d-security-users" mailing list

黃 世名 <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <BN6PR16MB0066C10C91C182D248406DF4B7EB0@BN6PR16MB0066.namprd16.prod.outlook.com>
Hi,

I am curious about how to boost audit log performance. Regardless of mode Serial or Concurrent, I find that there is a huge bottleneck in audit log engine.
After enabling audit log engine, Modsecurity's requests per second can decrease from 1000 to 270 with command wrk.  In addition to this, when using command "wrk -t1 -c10 -d60s http:/uri", nginx processes would not response any more and become unavailable to normal request. I use v3 master(libmodsecuriy: 738e328, nginx-module-modsecurity: 4b50399, nginx: 1.14.0) as my test bed. Like Nginx, instead of writing a log entry for every request to disk immediately, it can buffer entries in memory and write them to disk as a group. Is it possible to apply this mechanism to audit log engine or there having another approach to solve this challenge?

Regards,
Daniel

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.