• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion
  • Inviting everyone to the UX test of a new security feature in the WP Toolkit
    For WordPress site owners, threats posed by hackers are ever-present. Because of this, we are developing a new security feature for the WP Toolkit. If the topic of WordPress website security is relevant to you, we would be grateful if you could share your experience and help us test the usability of this feature. We invite you to join us for a 1-hour online session via Google Meet. Select a convenient meeting time with our friendly UX staff here.

Issue ModSecurity for Plesk 12.5.30

johnny a

New Pleskian
I installed ModSecurity through the add components section in plesk. I've it configured to be only in detection mode (for now while I test). I'm using the Atomic Basic ModSecurity rule set. It seems to be working fine. I see stuff getting written to the logs. The issue I'm having is that I can't view the logs from within plesk itself.
Like when you go to a domain -> Web Application Firewall then click on the ModSecurity Log File link. It's always blank. I can only view the logs from being on the server and opening the text file. Which is fine but...

That brings me to my next problem. The logs are located (plesk root dir)/parallels/plesk/modsecurity/vhosts The problem here is that the folders for each domain aren't named after the domain. They're named in a long string of numbers and letters. I'm guessing that corresponds to a domain ID somewhere inside of plesk or in IIS? Is there somewhere that I can find which string belongs to which domain? I'm ok with not being able to view the logs from the plesk interface, but I'd like to at least easily be able to view them when I'm on the server.

Has anyone run into this issue?
 
Still having the same issue with the logs. Should I try turning ModSecurity from Detection mode to "On"? Anyone else out there have ModSecurity running with Plesk and IIS?
 
Back
Top