Re: capturing user logins

Manuel Spartan <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <[email protected]>
Hi Doug, as said before the easiest way is setup a rule to extract the info and parse it in elk or whatever you use, alternatively you can create an environment variable in the rule to get the info and use a conditional apache custom log to save the extracted info if the env var is set in the format you need so you have a clean file with the info.

https://github.com/SpiderLabs/ModSecurity/wiki/Reference-Manual-(v2.x)#setenv

Cheers!

Sent from my iPhone

> On 25 Mar 2019, at 16:31, Doug Erwin <[email protected]> wrote:
> 
> I would definitely welcome some help.  If I understand correctly, it writes everything to the event viewer -> application log.  Is there a way to redirect that just write a log file to the file system, maybe even a separate log just for these user logins?
>  
> Also, is there an online tutorial about writing rules for modsecurity?  Maybe something on youtube?
>  
> Doug
>  
> Doug Erwin
> President
> TTP Solutions / TheTradingPortal.com
> [email protected]
> Office:  615-469-0409
> Cell:       615-498-4756
> <image001.png>
>  
> From: Chaim Sanders <[email protected]> 
> Sent: Monday, March 25, 2019 2:54 PM
> To: [email protected]
> Subject: Re: [mod-security-users] capturing user logins
>  
> Yes,
> You can make a rule that checks if the parameter with the username is provided and log that. You can then parse the log or use MLogc to move things to third party servers like elasticsearch. Let me know if that makes sense or you need more help.
> Thanks,
> - Chaim
>  
> On Mon, Mar 25, 2019 at 3:01 PM Doug Erwin <[email protected]> wrote:
> Hi all, I am new to modsecurity but I would like to use it to capture user logins so that I could build a history of user access over time.  Is there a way to do that?  I am pretty sure that this would be a new special or custom rule.  Any thoughts on this?
>  
> Thanks in advance.
>  
> Doug
>  
> Doug Erwin
> President
> TTP Solutions / TheTradingPortal.com
> [email protected]
> Office:  615-469-0409
> Cell:       615-498-4756
> <image001.png>
>  
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
> 
>  
> --
> -- 
> Chaim Sanders
> http://www.ChaimSanders.com
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.