[packages/apache-mod_security] - JSON audit log by default (one object per line, same format as libmodsecurity v3)

arekm arekm at pld-linux.org
Sat Sep 12 00:52:15 CEST 2026


commit d8a00cb8de8175d7544e60154735a56aa6988ead
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Sat Sep 12 00:48:36 2026 +0200

    - JSON audit log by default (one object per line, same format as libmodsecurity v3)

 apache-mod_security.logrotate |  7 +++++++
 pld-config.patch              | 13 +++++++------
 2 files changed, 14 insertions(+), 6 deletions(-)
---
diff --git a/apache-mod_security.logrotate b/apache-mod_security.logrotate
new file mode 100644
index 0000000..686d899
--- /dev/null
+++ b/apache-mod_security.logrotate
@@ -0,0 +1,7 @@
+/var/log/httpd/modsec_audit.json {
+	olddir /var/log/archive/httpd
+	missingok
+	notifempty
+	# serial audit log fd is opened once by the httpd parent and not reopened on graceful reload
+	copytruncate
+}
diff --git a/pld-config.patch b/pld-config.patch
index a75eeb8..62d6ce9 100644
--- a/pld-config.patch
+++ b/pld-config.patch
@@ -1,8 +1,8 @@
 PLD paths for the shipped engine config (logs/ is ServerRoot-relative as in httpd.conf; SecUnicodeMapFile is not);
-SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
+SecRuleEngine On is the PLD default, upstream ships DetectionOnly; JSON audit log (one object per line) for tooling.
 
---- modsecurity-v2.9.14/modsecurity.conf-recommended	2026-09-10 23:55:11.935535749 +0200
-+++ modsecurity-v2.9.14/modsecurity.conf-recommended	2026-09-10 23:55:11.936658773 +0200
+--- modsecurity-v2.9.14/modsecurity.conf-recommended	2026-09-12 00:43:20.566416060 +0200
++++ modsecurity-v2.9.14/modsecurity.conf-recommended	2026-09-12 00:43:20.566632528 +0200
 @@ -4,7 +4,7 @@
  # only to start with, because that minimises the chances of post-installation
  # disruption.
@@ -46,12 +46,13 @@ SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
  #SecDebugLogLevel 3
  
  
-@@ -202,10 +202,10 @@
+@@ -202,10 +202,11 @@
  # assumes that you will use the audit log only ocassionally.
  #
  SecAuditLogType Serial
 -SecAuditLog /var/log/modsec_audit.log
-+SecAuditLog logs/modsec_audit.log
++SecAuditLogFormat JSON
++SecAuditLog logs/modsec_audit.json
  
  # Specify the path for concurrent audit logging.
 -#SecAuditLogStorageDir /opt/modsecurity/var/audit/
@@ -59,7 +60,7 @@ SecRuleEngine On is the PLD default, upstream ships DetectionOnly.
  
  
  # -- Miscellaneous -----------------------------------------------------------
-@@ -227,7 +227,7 @@
+@@ -227,7 +228,7 @@
  # to properly map encoded data to your language. Properly setting
  # these directives helps to reduce false positives and negatives.
  #
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/apache-mod_security.git/commitdiff/ac1dc6877099d70bd39d3023a743f0a6c0deb26f



More information about the pld-cvs-commit mailing list