# Modsecurity Log Grok Filter

**URL:** <https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057>\
**Category:** Logstash\
**Created:** [November 20, 2020, 3:40am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057 "2020-11-20T03:40:26Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![reza\_naipospos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reza_naipospos/32/76767_2.png) [@reza\_naipospos](https://discuss.elastic.co/u/reza_naipospos)\
**Post date:** [November 20, 2020, 3:40am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/1 "2020-11-20T03:40:26Z")

</div>

I make grok filter with this condition but noting show anything on grok debugger. Log format is Modsecurity audit log  
(?%{YEAR}[./]%{MONTHNUM}[./]%{MONTHDAY} %{TIME}) [%{LOGLEVEL:severity}] %{POSINT:pid}#%{NUMBER:threadid}: \*%{NUMBER:connectionid} %{GREEDYDATA:attack}, client: %{IP:client}, server: %{GREEDYDATA:server}"}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2020, 3:42am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/2 "2020-11-20T03:42:38Z")

</div>

> [@reza\_naipospos](#):
>
> Log format is Modsecurity audit log

Showing an example of that would be helpful to match it with your grok.

---

<div class="post-metadata">

**Author:** ![reza\_naipospos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reza_naipospos/32/76767_2.png) [@reza\_naipospos](https://discuss.elastic.co/u/reza_naipospos)\
**Post date:** [November 20, 2020, 3:49am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/3 "2020-11-20T03:49:42Z")

</div>

```auto
---vnLs12ze---A--
[14/Nov/2020:09:36:42 +0700] 1605321402 192.168.101.254 53704 192.168.223.22 443
---vnLs12ze---B--
GET /favicon.ico HTTP/1.1
Host: opr.pt-ssss.com
Sec-Fetch-Mode: no-cors
Sec-Fetch-Dest: image
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.193 Safari/537.36
Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8
Sec-Fetch-Site: same-origin
Referer: https://opr.pt-ssss.com/?q=%22%3E%3Cscript%3Ealert(1)%3C/script%3E%22
Accept-Encoding: gzip, deflate, br
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8

---vnLs12ze---D--

---vnLs12ze---E--
<html>\x0d\x0a<head><title>403 Forbidden</title></head>\x0d\x0a<body>\x0d\x0a<center><h1>403 Forbidden</h1></center>\x0d\x0a<hr><center>nginx/1.19.2</center>\x0d\x0a</body>\x0d\x0a</html>\x0d\x0a<!-- a padding to disable MSIE and Chrome friendly error page -->\x0d\x0a<!-- a padding to disable MSIE and Chrome friendly error page -->\x0d\x0a<!-- a padding to disable MSIE and Chrome friendly error page -->\x0d\x0a<!-- a padding to disable MSIE and Chrome friendly error page -->\x0d\x0a<!-- a padding to disable MSIE and Chrome friendly error page -->\x0d\x0a<!-- a padding to disable MSIE and Chrome friendly error page -->\x0d\x0a

---vnLs12ze---F--
HTTP/1.1 403
Server: nginx/1.19.2
Date: Sat, 14 Nov 2020 02:36:42 GMT
Content-Length: 555
Content-Type: text/html
Connection: keep-alive
Strict-Transport-Security: max-age=63072000

---vnLs12ze---H--
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?i)<script[^>]*>[\s\S]*?' against variable `REQUEST_HEADERS:Referer' (Value: `https://opr.pt-ssss.com/?q=%22%3E%3Cscript%3Ealert(1)%3C/script%3E%22' ) [file "/usr/local/nginx/conf/owasp-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "68"] [id "941110"] [rev ""] [msg "XSS Filter - Category 1: Script Tag Vector"] [data "Matched Data: <script> found within REQUEST_HEADERS:Referer: https://opr.pt-ssss.com/?q="><script>alert(1)</script>""] [severity "2"] [ver "OWASP_CRS/3.2.0"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "192.168.223.22"] [uri "/favicon.ico"] [unique_id "1605321402"] [ref "o29,8v341,69t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls"]
ModSecurity: Warning. Matched "Operator `Rx' with parameter `(?i:(?:<\w[\s\S]*[\s\/]|['\"](?:[\s\S]*[\s\/])?)(?:on(?:d(?:e(?:vice(?:(?:orienta|mo)tion|proximity|found|light)|livery(?:success|error)|activate)|r(?:ag(?:e(?:n(?:ter|d)|xit)|(?:gestur|leav)e|start|d (3146 characters omitted)' against variable `REQUEST_HEADERS:Referer' (Value: `https://opr.pt-ssss.com/?q=%22%3E%3Cscript%3Ealert(1)%3C/script%3E%22' ) [file "/usr/local/nginx/conf/owasp-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "205"] [id "941160"] [rev ""] [msg "NoScript XSS InjectionChecker: HTML Injection"] [data "Matched Data: <script found within REQUEST_HEADERS:Referer: https://opr.pt-ssss.com/?q="><script>alert(1)</script>""] [severity "2"] [ver "OWASP_CRS/3.2.0"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "192.168.223.22"] [uri "/favicon.ico"] [unique_id "1605321402"] [ref "o29,7v341,69t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls"]
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:ANOMALY_SCORE' (Value: `10' ) [file "/usr/local/nginx/conf/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "80"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [data ""] [severity "2"] [ver "OWASP_CRS/3.2.0"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.168.223.22"] [uri "/favicon.ico"] [unique_id "1605321402"] [ref ""]

---vnLs12ze---I--

---vnLs12ze---J--

---vnLs12ze---Z--       

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2020, 3:49am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/4 "2020-11-20T03:49:59Z")

</div>

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![reza\_naipospos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reza_naipospos/32/76767_2.png) [@reza\_naipospos](https://discuss.elastic.co/u/reza_naipospos)\
**Post date:** [November 20, 2020, 3:54am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/5 "2020-11-20T03:54:41Z")

</div>

ok sorry, i was format my code in question

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2020, 3:55am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/6 "2020-11-20T03:55:47Z")

</div>

Thanks!

Just to be clear, that entire block of code above is _one_ log entry?

---

<div class="post-metadata">

**Author:** ![reza\_naipospos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reza_naipospos/32/76767_2.png) [@reza\_naipospos](https://discuss.elastic.co/u/reza_naipospos)\
**Post date:** [November 20, 2020, 3:56am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/7 "2020-11-20T03:56:17Z")

</div>

yes is one log entry

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2020, 4:02am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/8 "2020-11-20T04:02:57Z")

</div>

Yikes, that's pretty unfriendly.

Ok you will need to use a [multiline codec](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-multiline.html) on your input to create a single line entry you can more easily grok. You should be able to match that on the `---vnLs12ze---Z--` pattern, as it seems to repeat (bar the last letter).

---

<div class="post-metadata">

**Author:** ![reza\_naipospos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reza_naipospos/32/76767_2.png) [@reza\_naipospos](https://discuss.elastic.co/u/reza_naipospos)\
**Post date:** [November 20, 2020, 4:16am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/9 "2020-11-20T04:16:48Z")

</div>

this is on json format

```auto
{"transaction":{"client_ip":"192.168.101.85","time_stamp":"Fri Nov 20 09:46:01 2020","server_id":"5dc7f7ecb861cb00b5644894e1ab67235e99ba3c","client_port":49738,"host_ip":"192.168.75.22","host_port":443,"unique_id":"1605840361","request":{"method":"GET","http_version":1.1,"uri":"/favicon.ico","headers":{"Host":"sample.domain.com","Sec-Fetch-Mode":"no-cors","Sec-Fetch-Dest":"image","Connection":"keep-alive","User-Agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36","Accept":"image/avif,image/webp,image/apng,image/*,*/*;q=0.8","Sec-Fetch-Site":"same-origin","Referer":"https://sample.domain.com/?q=%22%3E%3Cscript%3Ealert(1fffsadasccc)%3C/script%3E%22","Accept-Encoding":"gzip, deflate, br","Accept-Language":"en-GB,en-US;q=0.9,en;q=0.8"}},"response":{"body":"<html>\r\n<head><title>403 Forbidden</title></head>\r\n<body>\r\n<center><h1>403 Forbidden</h1></center>\r\n<hr><center>nginx/1.19.2</center>\r\n</body>\r\n</html>\r\n<!-- a padding to disable MSIE and Chrome friendly error page -->\r\n<!-- a padding to disable MSIE and Chrome friendly error page -->\r\n<!-- a padding to disable MSIE and Chrome friendly error page -->\r\n<!-- a padding to disable MSIE and Chrome friendly error page -->\r\n<!-- a padding to disable MSIE and Chrome friendly error page -->\r\n<!-- a padding to disable MSIE and Chrome friendly error page -->\r\n","http_code":403,"headers":{"Server":"nginx/1.19.2","Date":"Fri, 20 Nov 2020 02:46:01 GMT","Content-Length":"555","Content-Type":"text/html","Connection":"keep-alive","Strict-Transport-Security":"max-age=63072000"}},"producer":{"modsecurity":"ModSecurity v3.0.4 (Linux)","connector":"ModSecurity-nginx v1.0.1","secrules_engine":"Enabled","components":["OWASP_CRS/3.2.0\""]},"messages":[{"message":"XSS Filter - Category 1: Script Tag Vector","details":{"match":"Matched \"Operator `Rx' with parameter `(?i)<script[^>]*>[\\s\\S]*?' against variable `REQUEST_HEADERS:Referer' (Value: `https://sample.domain.com/?q=%22%3E%3Cscript%3Ealert(1fffsadasccc)%3C/script%3E%22' )","reference":"o29,8v341,80t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls","ruleId":"941110","file":"/usr/local/nginx/conf/owasp-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf","lineNumber":"68","data":"Matched Data: <script> found within REQUEST_HEADERS:Referer: https://sample.domain.com/?q=\"><script>alert(1fffsadasccc)</script>\"","severity":"2","ver":"OWASP_CRS/3.2.0","rev":"","tags":["application-multi","language-multi","platform-multi","attack-xss","paranoia-level/1","OWASP_CRS","OWASP_CRS/WEB_ATTACK/XSS","WASCTC/WASC-8","WASCTC/WASC-22","OWASP_TOP_10/A3","OWASP_AppSensor/IE1","CAPEC-242"],"maturity":"0","accuracy":"0"}},{"message":"NoScript XSS InjectionChecker: HTML Injection","details":{"match":"Matched \"Operator `Rx' with parameter `(?i:(?:<\\w[\\s\\S]*[\\s\\/]|['\\\"](?:[\\s\\S]*[\\s\\/])?)(?:on(?:d(?:e(?:vice(?:(?:orienta|mo)tion|proximity|found|light)|livery(?:success|error)|activate)|r(?:ag(?:e(?:n(?:ter|d)|xit)|(?:gestur|leav)e|start|d (3146 characters omitted)' against variable `REQUEST_HEADERS:Referer' (Value: `https://sample.domain.com/?q=%22%3E%3Cscript%3Ealert(1fffsadasccc)%3C/script%3E%22' )","reference":"o29,7v341,80t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls","ruleId":"941160","file":"/usr/local/nginx/conf/owasp-crs/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf","lineNumber":"205","data":"Matched Data: <script found within REQUEST_HEADERS:Referer: https://sample.domain.com/?q=\"><script>alert(1fffsadasccc)</script>\"","severity":"2","ver":"OWASP_CRS/3.2.0","rev":"","tags":["application-multi","language-multi","platform-multi","attack-xss","paranoia-level/1","OWASP_CRS","OWASP_CRS/WEB_ATTACK/XSS","WASCTC/WASC-8","WASCTC/WASC-22","OWASP_TOP_10/A3","OWASP_AppSensor/IE1","CAPEC-242"],"maturity":"0","accuracy":"0"}},{"message":"Inbound Anomaly Score Exceeded (Total Score: 10)","details":{"match":"Matched \"Operator `Ge' with parameter `5' against variable `TX:ANOMALY_SCORE' (Value: `10' )","reference":"","ruleId":"949110","file":"/usr/local/nginx/conf/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf","lineNumber":"80","data":"","severity":"2","ver":"OWASP_CRS/3.2.0","rev":"","tags":["application-multi","language-multi","platform-multi","attack-generic"],"maturity":"0","accuracy":"0"}}]}}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 20, 2020, 4:18am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/10 "2020-11-20T04:18:02Z")

</div>

Oh, so you can make it a json format too? That's heaps easier as you can just use the [json codec](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-json.html)!

---

<div class="post-metadata">

**Author:** ![reza\_naipospos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reza_naipospos/32/76767_2.png) [@reza\_naipospos](https://discuss.elastic.co/u/reza_naipospos)\
**Post date:** [November 20, 2020, 4:21am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/11 "2020-11-20T04:21:28Z")

</div>

ok thanks for your help. I will try

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2020, 4:21am UTC](https://discuss.elastic.co/t/modsecurity-log-grok-filter/256057/12 "2020-12-18T04:21:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
