owasp-modsecurity / owasp-modsecurity/ModSecurity

ModSecurity v2.9.12 “Skipping request since there is nowhere to write to” despite valid SecAuditLog configuration

Open
#3,446 10 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

2.x
Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

Hi,

On Amazon Linux 2023 (AArch64) using ModSecurity v2.9.12 with Apache 2.4.65, audit logs fail to write even with valid configuration and writable path.
Debug logs report:

[15/Oct/2025:13:55:40.259888 +0200] [10.104.19.109/sid#aaaae39e0938][rid#ffff18026b80][/health/status][4] Audit log: Logging this transaction. [15/Oct/2025:13:55:40.259892 +0200] [10.104.19.109/sid#aaaae39e0938][rid#ffff18026b80][/health/status][4] Audit log: Skipping request since there is nowhere to write to.

Environment:

OS: Amazon Linux 2023 (latest patched)

Architecture: aarch64

Apache version: httpd 2.4.65-1.amzn2023.0.1

ModSecurity version: 2.9.12-1.amzn2023.0.1

SELinux: disabled

Config (minimal reproduction):

<IfModule security2_module>
  SecRuleEngine On
  SecRequestBodyAccess On
  SecResponseBodyAccess Off
  SecDebugLog /var/log/httpd/modsec_debug_test.log
  SecDebugLogLevel 5
  SecAuditEngine On
  SecAuditLogRelevantStatus ".*"
  SecAuditLogType Serial
  SecAuditLog /var/log/httpd/modsec_audit_test.log
  SecRule ARGS:testparam "@streq attack" "id:1,phase:2,deny,log,auditlog,msg:action_detected,ctl:debugLogLevel=9"
</IfModule>

Apache reports Syntax OK

Steps to Reproduce:

Install httpd + mod_security on Amazon Linux 2023.

Apply minimal config above.

Restart httpd and send any request.

Observe debug log.

Expected Result:
Audit log file (SecAuditLog) should receive entries.

Actual Result:
Log is skipped with nowhere to write to even though the file exists and is writable.

Additional Notes:

No SELinux denials or permission errors.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the report with the minimal configuration, especially SecAuditLog /var/log/httpd/modsec_audit_test.log and SecDebugLog /var/log/httpd/modsec_debug_test.log, then inspect the audit-log handling entry point that emits “nowhere to write to.” Done means requests produce entries in the configured audit log without permission or SELinux errors.

Written by the indexing model from the issue text.

Assessment

Tech stack
apache, linux
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.