This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No data is Web Server Protection Log (XG v18.0 MR3)

I created a fresh WAF rule on the firewall.  The log option disappears and I am not getting any data for incoming connection in the 'firewall' or 'web server protection' logs.

Here is a snippet of the reverseproxy.log if that helps.


AH00112: Warning: DocumentRoot [/sdisk/waffiles/29adbea3b375c77c663bad62c8e1c359] does not exist

[Sun Nov 15 16:36:51.535116 2020] [mpm_worker:notice] [pid 30047:tid 140501021796160] AH00295: caught SIGTERM, shutting down

AH00112: Warning: DocumentRoot [/sdisk/waffiles/29adbea3b375c77c663bad62c8e1c359] does not exist

[Sun Nov 15 16:36:53.000261 2020] [security2:notice] [pid 391:tid 140599894681408] ModSecurity for Apache/2.9.3 (http://www.modsecurity.org/) configured.

[Sun Nov 15 16:36:53.000408 2020] [security2:notice] [pid 391:tid 140599894681408] ModSecurity: APR compiled version="1.7.0"; loaded version="1.7.0"

[Sun Nov 15 16:36:53.000424 2020] [security2:notice] [pid 391:tid 140599894681408] ModSecurity: PCRE compiled version="8.43 "; loaded version="8.43 2019-02-23"

[Sun Nov 15 16:36:53.000437 2020] [security2:notice] [pid 391:tid 140599894681408] ModSecurity: LIBXML compiled version="2.9.9"

[Sun Nov 15 16:36:53.000448 2020] [security2:notice] [pid 391:tid 140599894681408] ModSecurity: Status engine is currently disabled, enable it by set SecStatusEngine to On.

[Sun Nov 15 16:36:54.007882 2020] [mpm_worker:notice] [pid 393:tid 140599894681408] AH00292: Apache/2.4.25 (Unix) OpenSSL/1.0.2r-fips configured -- resuming normal operations

[Sun Nov 15 16:36:54.007997 2020] [core:notice] [pid 393:tid 140599894681408] AH00094: Command line: '/usr/apache/bin/httpd -E /log/reverseproxy.log'



This thread was automatically locked due to age.
Parents
  • Logging of WAF is always enabled. Seems like your WAF starts fine but does not getting any requests. 

    WAF is launched on Port 443 or Port 80. Check if there is no NAT Rule to bypass WAF.

    __________________________________________________________________________________________________________________

Reply
  • Logging of WAF is always enabled. Seems like your WAF starts fine but does not getting any requests. 

    WAF is launched on Port 443 or Port 80. Check if there is no NAT Rule to bypass WAF.

    __________________________________________________________________________________________________________________

Children
No Data