Re: nolog rule still logs

Bren via mod-security-users <[email protected]> Tue, 06 Apr 2021 19:57:20 +0000
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <1vUCpfbf6-_6GvXIiHUlBtT8vTQCpB96-6J8oUr7tAUO63Wcx6oAFogf9mtAkQpXMJOpmuww1HKPFzfPb_cEwmF_eTqyoiIguvyG1RvR0ZA=@protonmail.com>
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐

On Tuesday, April 6th, 2021 at 2:38 PM, Christian Folini <[email protected]> wrote:

> However, this only accounts for the audit log and you said you also got error-log messages and I could not explain those.

Hmm yeah, I enabled the error log again and those 403s are still being logged there:

nginx: 2021/04/06 15:46:06 [error] 17236#17236: *3835 [client 127.0.0.1] ModSecurity: Access denied with code 403 (phase 1). Matched "Operator `Rx' with parameter `/waf_health_check' against variable `REQUEST_FILENAME' (Value: `/waf_health_check' ) [file "/etc/openresty/modsecurity/exclusions.conf"] [line "3"] [id "1000"] [rev ""] [msg ""] [data ""] [severity "0"] [ver ""] [maturity "0"] [accuracy "0"] [hostname "127.0.0.1"] [uri "/waf_health_check"] [unique_id "1617738366"] [ref "o0,17v5,17"], client: 127.0.0.1, server: , request: "HEAD /waf_health_check HTTP/1.1", host: "www.testhost.com"

Nothing is being logged to the audit log though so that's good. I'll continue to investigate.

Bren


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/