ModSecurity + IIS - Disabling Event Logging

Osama Elnaggar <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CACva_gHZ8ajUyyCBw36XAFT-tdiPQVgvJLH8xAqjsMoU1ViHCA@mail.gmail.com>
Hi,

When running ModSecurity on IIS, I was wondering if there was any way to
disable event logging for audit logs.  Is there some option to disable
this?  I would prefer that only health-related data be sent to the Event
Log such as if ModSecurity failed to start, etc. while normal audit logs be
sent to a file that I can then forward to my SIEM.  I’m able to send audit
logs to another file but they are still mirrored to the event log as well.

Also, from my limited testing, it appears that arguments are not sanitized
when sent to the Windows Event Log which is a concern.  The normal audit
log (modsec_audit.log) sanitizes them properly but not the event log.  Is
this a known issue?

Thanks.

-- 
Osama Elnaggar

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.