ModSecurity Log Rotation with Splunk Indexing Issues
Issue
- When using rotatelogs to rotate ModSecurity audit logs hourly, Splunk encounters issues indexing the rotated log files because they do not start with the required SecAuditLogParts A section. This prevents Splunk from properly parsing and indexing ModSecurity logs.
Environment
- Apache Web Server (httpd)
- 2.4.x
- RHEL
- 9.5
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.