Skip to main content

CPANEL-42469 - New cPanel installs ModSec Tools Hits empty/stopped

Comments

8 comments

  • cPRex Jurassic Moderator
    Hey there! It's not completely clear to me what the question is - what are you trying to fix on the system? Are you expecting more ModSecurity logs to be happening?
    0
  • indiemark
    Yes. Usually (on another cPanel server I have that is not using Ruid but instead CloudLinux) there lots of hits in the ModSec Tools area. Same rules are applied, so I should be seeing similar levels of hits from bots etc. But I see NOTHING on one of my new installs and only a couple hours worth of hits on the other (I had moved some sites before realising I should enable Ruid). I'm fairly certain it's RUID and the changes to the logs that has broken this and that would link up anecdotally with the brief amount of hits in the log and other RUID/Modsec issues I've read about with cpanel from google searches. Is there a troubleshooting guide I can go to for Modsec/ruid to make sure cPanel's UI is ingesting them properly? I "think" ModSec itself is working, and if I manually look at the logs that also seems to be the case, but I would like the visibility in cPanel so I can more easily identify false positives if I get customer complaints.
    0
  • indiemark
    So to be clearer maybe: Cpanel A -- has CloudLinux, no RUID enabled. ModSec Tools -> lots of hits listed no problems. cPanel B -- Alma, RUID enabled AFTER moving a few sites. ModSec Tools -> brief list of Hits from a few days back but stopped when I enabled RUID in EA cPanel C -- Alma, RUID enabled right off the bat before moving sites. ModSec Tools -> Hits are empty All using the same OWASP ruleset, enabled. On cPanel B and C I've found the actual ModSec logs and it looks like there is action happening, just not reporting to cPanel GUI.
    0
  • cPRex Jurassic Moderator
    I wonder if it's just related to the presence of RUID:
    0
  • indiemark
    Agreed, that is the likely case. But I thought there were scripts or something to go and collect these logs so they showed up the ModSec Tools "hits" area?
    0
  • cPRex Jurassic Moderator
    I found a more direct case that indicates our developers are already working on this issue:
    0
  • cPRex Jurassic Moderator
    Update - I have confirmed this will be fixed in version 110, and there is a backport request to version 102 in the development pipeline as well.
    0
  • cPRex Jurassic Moderator
    Update - 110.0.0 and 108.0.14 have this resolved.
    0

Please sign in to leave a comment.