Filter ModSec hits list table by severity, please
Hi, would it be possible for you guys to add a filter under: Security Center > ModSecurity Tools > Hits List
It would be so much faster to retrieve the information if we could filter out the useless rows. Just add a drop down menu "Filter by severity":
- Any severity
- At least "warning"
- At least "critical"
Also (unrelated, but while you're at it) is it possible for you guys to retain the number of elements per page in the browser's storage? 10 is useless for production servers. We can easily get 10 rows in there within a minute so I always set it to 100 (please add an option for 250 as well) but then when I move to another page and come back, I have to set it again. This does not seem like it, but it waste lots of time when I have to do that every couple hours.
e.g. instead of all these (there are more than 100 of these in a row) we could filter by "at least critical" and only get a few of those lines for that IP and that's it. No need to get all the empty severity lines or the lines that say after every hit that the inbound anomaly score is now higher than 5, this is completely useless to us.

-
Hey there! Not a bad idea - I'll bring it up with the team on Friday and I'll let you know what I find out!
1 -
Thank you distinguished dinosaur mod.
0 -
I tested this out with the team on Friday and it actually looks like you can use the existing search bar on the page to do this. You can just enter "warning" and press enter in the search bar and then it will filter the content on the page based on that.
Would that work for you?
0 -
How does that solve any of the things I asked almost 2 weeks ago? I feel brushed off and why is it so hard for cPanel to come up with a simple and functional interface in 2025? I'm not asking something hard here. Add 250, add 500, don't list repetitive and empty rows, keep settings in session or in browser storage so I don't have to re-enter all this every couple hours. Read my initial message, I think you forgot 80% of it.
0 -
Oh for sure, there's multiple other things there, but I figured I could get them all at once if there was an interface tweak.
For the filtering, is that search box good enough for what you need?
0 -
Well, yes, if I search for "critical" then I only get the critical severity ones, which saves me some time, but there is room for improvement with the rest of this form like stated in my first post. The thing that makes me waste the most amount of time is that some IP addresses are repeated for up to like 50 times in a row, so they take a full "100" items page all to themselves (and even two "100" pages in some cases! see attached picture in the first post). Can you imagine how long it takes to go over a day's worth of those? I would like for IP addresses of severity "critical" to only show once, not 50 times in a row. This is useless information that makes me waste a lot of time.
For some of those tweaks, I don't understand how it could take more than 8 seconds of your time. For example, adding "250" and "500" to the "Page Size" drop down menu takes less time to implement than to read this message.
0 -
I'm with you on the paging - I've created case CPANEL-47135 for the team to check that out.
I'm not sure I'll be able to get traction on the "don't show duplicates" issue. What exactly would that look like for you on the page? If there are 50 lines or greater of the same IP triggering the exact same rule, a button appears that lets you shrink that list? Something along those lines?
0 -
I would honestly want all duplicate rows to just not show. A filter checkbox (default to OFF) at the top near the "Page Size" drop down menu allowing me to hide all duplicate rows would be an (IMHO) easy to implement solution. Look at my screenshot in the first post. What is the purpose of repeating 50 times that one IP address anomaly score exceeded 5? It exceeds 5 like 50 times in a row, I think I got it after the first time it displayed that. Because of those 50 lines, I can't see other offending IP addresses and so I have to go on page 2, then 3, then 4, then 5, also partially because "100" is the maximum amount of lines per page, which is ridiculously low for an average production server in 2025.
0 -
That works! Case CPANEL-47136 created for that!
It would likely be at least 2 weeks before the teams check this out, but if you ever want an update, just ask!
0 -
Thanks for taking care of passing the information to improve our sysadmin experience. I would also like to underline the fact that it's still a huge mess to sign in on support.cpanel.net despite it being what, a year now with the new login system? It takes like anywhere from 6 to 11 clicks to sign in. I'm getting redirected to enter my password, then there's an empty page with just a button to continue, but then it asks me to sign in again, etc... it goes in circle 2-3 times and then I'm suddenly in. I also saw that on this very topic thread there was a spam posted on Sunday, but somebody deleted it just a few minutes after it was posted. This shows how this horrible new login system is not even playing a major role in upgrading the forums security and this, despite the fact that it's super frustrating to use... for humans. Spam and bots still post on here.
0 -
Yeah, unfortunately that's still a thing. It was being worked on for a bit, but ultimately they have decided to completely replace the login tools with something new. I'm not sure when that's going to happen as there are a few other behind-the-scenes things that need to happen first.
0 -
I hope you will see this as a constructive feedback. I'm sorry for being extremely blunt, but what are you guys doing with all the money that we pay every month? I'm not posting this to insult cPanel staff, but I'm feeling quite upset to see that there is next to no update on both complex and minor defects month after month despite the fact that I continue to pay more every year. The price keeps increasing and the software looks more and more broken every year. Again, I hope that you see this as a constructive feedback rather than an insult. I've been a cPanel customer for over 15 years and the product was so much better a decade ago.
0 -
Update - the developers don't want to change the page size beyond 100 as that would be inconsistent with other areas of the product. However, they are going to take a look eliminating duplicates, which should also greatly reduce the need for those large page sizes.
I'll likely hear a bit more about this in our improvements meeting on Monday.
0 -
This answer is quite surprising, given how that particular component already is inconsistent throughout WHM (and has been for years)... and do you want to know what's sad about it? The older that pagination component is, the more functional. The newer, the less functional... e.g.:
Pagination template #1 (new, can't set anything and is constrained to 100 elements per page) :

Pagination template #2 (older, more functional: can define exactly how many items per page) :

Pagination template #3 :

Pagination template #4 :
0
Please sign in to leave a comment.
Comments
14 comments