I have my modsec installations using serial mode, and am using the universal forwarder to feed the audit.log to Splunk. The source appears in the Splunk search but the ModSecurity app sees nothing.
Yes, I have updated the source_type. What now?
... View more