Skip to content

SecAuditLogRelevantStatus conf is not working? #3433

@opsmeta

Description

@opsmeta

Describe the bug

Image SecAuditLogRelevantStatus "^(?:5|4(?!04))" Already configured,But still record the logs of 2xx and 3xx status codes.

As shown in the figure:
Image

Logs and dumps

Output of:

  1. DebugLogs (level 9) 0
  2. AuditLogs /tmp/modsec/audit.log
  3. Error logs

Expected behavior

SecAuditLog and SecAuditLogStorageDir Only record logs for modsec 4xx and 5xx.

Server (please complete the following information):

  • ModSecurity latest with nginx-connector latest 20250811 master
  • WebServer: nginx version: openresty/1.21.4.4
  • OS (and distro): CentOS Linux release 7.9.2009 (Core)

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.xRelated to ModSecurity version 3.x

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions