[packages/apache-mod_security] - JSON audit log by default (one object per line, same format as libmodsecurity v3)
arekm
arekm at pld-linux.org
Sat Sep 12 00:52:15 CEST 2026
commit d8a00cb8de8175d7544e60154735a56aa6988ead
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Sat Sep 12 00:48:36 2026 +0200
- JSON audit log by default (one object per line, same format as libmodsecurity v3)
apache-mod_security.logrotate | 7 +++++++
pld-config.patch | 13 +++++++------
2 files changed, 14 insertions(+), 6 deletions(-)
---
diff --git a/apache-mod_security.logrotate b/apache-mod_security.logrotate
new file mode 100644
index 0000000..686d899
--- /dev/null
+++ b/apache-mod_security.logrotate
@@ -0,0 +1,7 @@
+/var/log/httpd/modsec_audit.json {
+ olddir /var/log/archive/httpd
+ missingok
+ notifempty
+ # serial audit log fd is opened once by the httpd parent and not reopened on graceful reload
+ copytruncate
+}
diff --git a/pld-config.patch b/pld-config.patch
index a75eeb8..62d6ce9 100644
--- a/pld-config.patch
+++ b/pld-config.patch
@@ -1,8 +1,8 @@
PLD paths for the shipped engine config (logs/ is ServerRoot-relative as in httpd.conf; SecUnicodeMapFile is not);
-SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
+SecRuleEngine On is the PLD default, upstream ships DetectionOnly; JSON audit log (one object per line) for tooling.
---- modsecurity-v2.9.14/modsecurity.conf-recommended 2026-09-10 23:55:11.935535749 +0200
-+++ modsecurity-v2.9.14/modsecurity.conf-recommended 2026-09-10 23:55:11.936658773 +0200
+--- modsecurity-v2.9.14/modsecurity.conf-recommended 2026-09-12 00:43:20.566416060 +0200
++++ modsecurity-v2.9.14/modsecurity.conf-recommended 2026-09-12 00:43:20.566632528 +0200
@@ -4,7 +4,7 @@
# only to start with, because that minimises the chances of post-installation
# disruption.
@@ -46,12 +46,13 @@ SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
#SecDebugLogLevel 3
-@@ -202,10 +202,10 @@
+@@ -202,10 +202,11 @@
# assumes that you will use the audit log only ocassionally.
#
SecAuditLogType Serial
-SecAuditLog /var/log/modsec_audit.log
-+SecAuditLog logs/modsec_audit.log
++SecAuditLogFormat JSON
++SecAuditLog logs/modsec_audit.json
# Specify the path for concurrent audit logging.
-#SecAuditLogStorageDir /opt/modsecurity/var/audit/
@@ -59,7 +60,7 @@ SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
# -- Miscellaneous -----------------------------------------------------------
-@@ -227,7 +227,7 @@
+@@ -227,7 +228,7 @@
# to properly map encoded data to your language. Properly setting
# these directives helps to reduce false positives and negatives.
#
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/apache-mod_security.git/commitdiff/ac1dc6877099d70bd39d3023a743f0a6c0deb26f
More information about the pld-cvs-commit
mailing list