<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ModSecurity App not reporting in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/ModSecurity-App-not-reporting/m-p/73876#M4672</link>
    <description>&lt;P&gt;I have the modsecurity app installed and all the third party apps installed in /opt/splunk/etc/apps. Data is being sent to splunk with the correct source and sourcetype, but the app doesn't create any charts. Any specific steps to complete the install?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2012 17:10:08 GMT</pubDate>
    <dc:creator>pfleetwood</dc:creator>
    <dc:date>2012-02-17T17:10:08Z</dc:date>
    <item>
      <title>ModSecurity App not reporting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/ModSecurity-App-not-reporting/m-p/73876#M4672</link>
      <description>&lt;P&gt;I have the modsecurity app installed and all the third party apps installed in /opt/splunk/etc/apps. Data is being sent to splunk with the correct source and sourcetype, but the app doesn't create any charts. Any specific steps to complete the install?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2012 17:10:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/ModSecurity-App-not-reporting/m-p/73876#M4672</guid>
      <dc:creator>pfleetwood</dc:creator>
      <dc:date>2012-02-17T17:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: ModSecurity App not reporting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/ModSecurity-App-not-reporting/m-p/73877#M4673</link>
      <description>&lt;P&gt;I got it working. In the Manager --&amp;gt; Fields --&amp;gt; Field Aliases, there were two settings. I removed the entry with xforwardedfor completely and changed the remaining "srcip AS clientip2" to "srcip AS clientip". Works beautifully.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2012 18:10:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/ModSecurity-App-not-reporting/m-p/73877#M4673</guid>
      <dc:creator>pfleetwood</dc:creator>
      <dc:date>2012-02-24T18:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: ModSecurity App not reporting</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/ModSecurity-App-not-reporting/m-p/73878#M4674</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I also have the same problem. I can see the alert in the Overview Dashboard only in the window Modsec alert trend but don't get any data for modsec denied by ip or host. Splunk collects the data on a reverse proxy. Can this be the issue? (I also tried the above solution but without success...). Thanks &lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2013 13:44:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/ModSecurity-App-not-reporting/m-p/73878#M4674</guid>
      <dc:creator>vm</dc:creator>
      <dc:date>2013-03-28T13:44:57Z</dc:date>
    </item>
  </channel>
</rss>

