[packages/nginx] - mod_http_modsecurity: JSON audit log by default (one object per line)

arekm arekm at pld-linux.org
Sat Sep 12 00:52:01 CEST 2026


commit fc9b3808ecf13f32af436d84e6c29c61437e29f6
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Sat Sep 12 00:48:36 2026 +0200

    - mod_http_modsecurity: JSON audit log by default (one object per line)

 nginx-modsecurity-pld.patch | 13 +++++++------
 nginx-modsecurity.logrotate |  7 +++++++
 2 files changed, 14 insertions(+), 6 deletions(-)
---
diff --git a/nginx-modsecurity-pld.patch b/nginx-modsecurity-pld.patch
index a83ae8d..9a8b5fb 100644
--- a/nginx-modsecurity-pld.patch
+++ b/nginx-modsecurity-pld.patch
@@ -1,8 +1,8 @@
 PLD paths for the engine config copied from libmodsecurity modsecurity.conf-recommended;
-SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
+SecRuleEngine On is the PLD default, upstream ships DetectionOnly; JSON audit log (one object per line) for tooling.
 
---- a/nginx-modsecurity.conf	2026-09-11 08:50:17.243723202 +0200
-+++ b/nginx-modsecurity.conf	2026-09-11 08:50:17.246745296 +0200
+--- a/nginx-modsecurity.conf	2026-09-12 00:43:21.131284516 +0200
++++ b/nginx-modsecurity.conf	2026-09-12 00:43:21.133951561 +0200
 @@ -4,7 +4,7 @@
  # only to start with, because that minimises the chances of post-installation
  # disruption.
@@ -46,12 +46,13 @@ SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
  #SecDebugLogLevel 3
  
  
-@@ -249,10 +249,10 @@
+@@ -249,10 +249,11 @@
  # assumes that you will use the audit log only ocassionally.
  #
  SecAuditLogType Serial
 -SecAuditLog /var/log/modsec_audit.log
-+SecAuditLog /var/log/nginx/modsec_audit.log
++SecAuditLogFormat JSON
++SecAuditLog /var/log/nginx/modsec_audit.json
  
  # Specify the path for concurrent audit logging.
 -#SecAuditLogStorageDir /opt/modsecurity/var/audit/
@@ -59,7 +60,7 @@ SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
  
  
  # -- Miscellaneous -----------------------------------------------------------
-@@ -274,7 +274,7 @@
+@@ -274,7 +275,7 @@
  # to properly map encoded data to your language. Properly setting
  # these directives helps to reduce false positives and negatives.
  #
diff --git a/nginx-modsecurity.logrotate b/nginx-modsecurity.logrotate
new file mode 100644
index 0000000..bee5aaf
--- /dev/null
+++ b/nginx-modsecurity.logrotate
@@ -0,0 +1,7 @@
+/var/log/nginx/modsec_audit.json {
+	olddir /var/log/archive/nginx
+	missingok
+	notifempty
+	# libmodsecurity opens the serial audit log once; nginx reopen-logs (USR1) does not reopen it
+	copytruncate
+}
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/nginx.git/commitdiff/3c2e68460d264f57b5ca390d3b626e192fd7dbf4



More information about the pld-cvs-commit mailing list