For Logging Maintainer [;)] Please make the Protocoles (modsec_audit.log, modsec_debug.log etc) the same way as modsecurity-console(from Breach Security) !!! This art of protocoles are very efficent.
And the modsecurity protocoles from the waf have another rightmanagment for the Directory data as example (rwxrws---) for the chroot httpd user.