All Apps and Add-ons

ModSecurity App not reporting

pfleetwood
Engager

I have the modsecurity app installed and all the third party apps installed in /opt/splunk/etc/apps. Data is being sent to splunk with the correct source and sourcetype, but the app doesn't create any charts. Any specific steps to complete the install?

Tags (1)

vm
New Member

Hello,

I also have the same problem. I can see the alert in the Overview Dashboard only in the window Modsec alert trend but don't get any data for modsec denied by ip or host. Splunk collects the data on a reverse proxy. Can this be the issue? (I also tried the above solution but without success...). Thanks

0 Karma

pfleetwood
Engager

I got it working. In the Manager --> Fields --> Field Aliases, there were two settings. I removed the entry with xforwardedfor completely and changed the remaining "srcip AS clientip2" to "srcip AS clientip". Works beautifully.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...