All Apps and Add-ons

ModSecurity App not reporting

pfleetwood
Engager

I have the modsecurity app installed and all the third party apps installed in /opt/splunk/etc/apps. Data is being sent to splunk with the correct source and sourcetype, but the app doesn't create any charts. Any specific steps to complete the install?

Tags (1)

vm
New Member

Hello,

I also have the same problem. I can see the alert in the Overview Dashboard only in the window Modsec alert trend but don't get any data for modsec denied by ip or host. Splunk collects the data on a reverse proxy. Can this be the issue? (I also tried the above solution but without success...). Thanks

0 Karma

pfleetwood
Engager

I got it working. In the Manager --> Fields --> Field Aliases, there were two settings. I removed the entry with xforwardedfor completely and changed the remaining "srcip AS clientip2" to "srcip AS clientip". Works beautifully.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...