[Owasp-modsecurity-core-rule-set] Missing Component Signature / Version Information in Blocking Rules

Heinrich M. heinrichm001 at t-online.de
Thu Nov 17 13:27:14 UTC 2016


Hi,

while playing around with the rule set and adding some custom rules, I
found that the blocking rules miss the version tag within Apache's
error log. Is there a reason for this? As fas as I could see, every
other rule is tagged with [ver "OWASP_CRS/3.0.0"] but I may be missing
something. 

I'd like to grep for '[ver "OWASP_CRS/3.0.0"]' in order to separate log
entries from custom rules from the CRS rules. I know that this can also
be done by rule IDs but those regexes are hard ;-).

Regards,

Heinrich


More information about the Owasp-modsecurity-core-rule-set mailing list