# Parser for Modsecurity logs?

**URL:** <https://discuss.elastic.co/t/parser-for-modsecurity-logs/100672>\
**Category:** Logstash\
**Created:** [September 15, 2017, 10:43am UTC](https://discuss.elastic.co/t/parser-for-modsecurity-logs/100672 "2017-09-15T10:43:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Blason](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/blason/32/42284_2.png) [@Blason](https://discuss.elastic.co/u/Blason)\
**Post date:** [September 15, 2017, 10:43am UTC](https://discuss.elastic.co/t/parser-for-modsecurity-logs/100672/1 "2017-09-15T10:43:20Z")

</div>

Hi Guys,

Does any one have a parser or logstash configuration file built for modsecurity logs which is a open source WAF

These are the sample modsec logs

2017/09/15 06:07:57 [info] 43541#43541: _5 [client 192.168.1.50] ModSecurity: Warning. Matched "Operator `Rx' with parameter`(?i)\<[^\w\<\>]_(?:[^\<\>"'\s]_:)?[^\w\<\>]_(?:\W\*?s\W\*?c\W\*?r\W\*?i\W\*?p\W\*?t|\W\*?f\W\*?o\W\*?r\W\*?m|\W\*?s\W\*?t\W\*?y\W\*?l\W\*?e|\W\*?s\W\*?v\W\*?g|\W\*?m\W\*?a\W\*?r\W\*?q\W\*?u\W\*?e\W\*?e|(?:\W\*?l\W\*?i\W\*?n\W\*?k|\W\*?o (3246 characters omitted)' against variable `ARGS:param' (Value:`"\>' ) [file "/usr/local/owasp-modsecurity-crs-3.0.0/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "225"] [id "941160"] [rev "2"] [msg "NoScript XSS InjectionChecker: HTML Injection"] [data "Matched Data: \<script found within ARGS:param: "\>"] [severity "2"] [ver "OWASP\_CRS/3.0.0"] [maturity "1"] [accuracy "8"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP\_CRS/WEB\_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP\_TOP\_10/A3"] [tag "OWASP\_AppSensor/IE1"] [tag "CAPEC-242"] [ref "o2,7o19,8v12,28t:utf8toUnicode,t:urlDecodeUni,t:htmlEntityDecode,t:jsDecode,t:cssDecode,t:removeNulls"] [hostname "192.168.1.50"] [uri "/"] [unique\_id "150547007770.152744"], client: 192.168.1.50, server: [isn.net](http://isn.net), request: "GET /?param=%22%3E%3Cscript%3Ealert(1);%3C/script%3E HTTP/1.1", host: "[www.isn1.net](http://www.isn1.net)"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2017, 10:43am UTC](https://discuss.elastic.co/t/parser-for-modsecurity-logs/100672/2 "2017-10-13T10:43:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
