owasp-modsecurity / owasp-modsecurity/ModSecurity
Problem with logrotate: Log rotation writes to incorrect file
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 9.8k
- Forks
- 1.8k
- Avg merge
- 2h 46m
- Merged PRs (30d)
- 1
Description
Problem Description:
After configuring logrotate to handle ModSecurity log rotation, I encountered an unexpected issue. After the first rotation, logs are being written to the file modsec_audit.log.1 instead of modsec_audit.log. Additionally, all subsequent logs are appended to the modsec_audit.log.1 file, leading to potentially large log files.
Logrotate Configuration:
/var/log/modsec_audit.log {
daily
rotate 14
compress
delaycompress
missingok
notifempty
create 644 root root
sharedscripts
postrotate
/usr/sbin/service nginx reopenlogs >/dev/null 2>&1 || true
endscript
}
Steps to Reproduce the Issue:
- ModSecurity configuration adhering to recommendations.
- Logrotate configuration added in /etc/logrotate.d/modsec.
Expected Behavior:
Logs should be correctly rotated into the modsec_audit.log file with the proper rotation suffix.
Observed Behavior:
Logs are written to the modsec_audit.log.1 file after the first rotation, and subsequent logs are appended to the modsec_audit.log.1 file.
Environment:
Operating System: linux ubuntu 20.04
ModSecurity Version: V3
Logrotate Version: 3.14.0
Your assistance in addressing this matter and providing guidance or a fix would be greatly appreciated. Thank you!
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the reported behavior with the supplied /etc/logrotate.d/modsec configuration, ModSecurity V3, and nginx's reopenlogs command. Trace how the audit log is reopened after rotation; done means new entries continue in modsec_audit.log rather than modsec_audit.log.1.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp, linux, nginx, ubuntu
- Domain
- backend, observability-sre
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100