All Apps and Add-ons

ModSecurity App not reporting

pfleetwood
Engager

I have the modsecurity app installed and all the third party apps installed in /opt/splunk/etc/apps. Data is being sent to splunk with the correct source and sourcetype, but the app doesn't create any charts. Any specific steps to complete the install?

Tags (1)

vm
New Member

Hello,

I also have the same problem. I can see the alert in the Overview Dashboard only in the window Modsec alert trend but don't get any data for modsec denied by ip or host. Splunk collects the data on a reverse proxy. Can this be the issue? (I also tried the above solution but without success...). Thanks

0 Karma

pfleetwood
Engager

I got it working. In the Manager --> Fields --> Field Aliases, there were two settings. I removed the entry with xforwardedfor completely and changed the remaining "srcip AS clientip2" to "srcip AS clientip". Works beautifully.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...