modsecurity-parser icon indicating copy to clipboard operation
modsecurity-parser copied to clipboard

--version3 and libmodsecurity 3 parsing exceptions

Open matteocostantini opened this issue 1 year ago • 1 comments

Hy, 've compile libmodsecurity3 (3.0.9) and apache-connector. How resolve it?

----- modsec_audit events processed: 68 ----- ----- modsec_audit events skipped by INCLUDED/EXCLUDED options or INVALID: 0 ----- Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'messages' Exception in Graph TOP 10 Attacks intercepted 'messages' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception in Graph TOP 10 IP source addresses: 'remote_address' Exception in TOP 20 rule hits: 'audit_data' for transaction_id : - Exception in Graph TOP 10 Attacks intercepted 'audit_data' Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc Exception at modsec_save_xlsx() :'transaction_id', transaction_id :ZF3-elttbGFBrieJDfTmbQAAAAc

matteocostantini avatar May 12 '23 13:05 matteocostantini

I would need an example of audit log. Please anonymize at least few log entries and attach here to let me check.

molu8bits avatar May 12 '23 15:05 molu8bits