Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

idea: add suggestion on logging #80

Open
fzipi opened this issue Feb 15, 2023 · 5 comments
Open

idea: add suggestion on logging #80

fzipi opened this issue Feb 15, 2023 · 5 comments

Comments

@fzipi
Copy link
Member

fzipi commented Feb 15, 2023

@RedXanadu's presentation on our CRS Dublin 2023 summit proposed interesting questions. One idea was to add information about how to do logging, what is important, etc.

@dune73
Copy link
Member

dune73 commented Feb 16, 2023

Are the slides online already? Can you elaborate otherwise?

@lifeforms
Copy link
Member

I don't know the scope, but I'd LOVE if we had a tutorial for (centralized) log management!

@RedXanadu
Copy link
Member

RedXanadu commented Mar 20, 2023

This would be really great to see. I would definitely like to read this content as I want to learn how to perform this kind of logging/aggregation.

The context of the original proposal was: there is a lack of comprehensive, good documentation available on how to plug CRS+ModSecurity into systems like OpenSearch (formerly Kibana) and others.

Some vendors have their own proprietary solutions or internal/pay-walled documentation. There are some scattered guides available on the public internet, but I've not come across one that's complete or easy to follow.

It would be great if CRS could provide an A to Z, easy to follow, complete guide on how to do something along these lines. We've raised the idea before (coreruleset.org/docs/operation/log_handling/), but we've never had the knowledge and time to do anything about it.


What we need:

  • Someone with operational experience to document the steps on how to achieve this kind of setup.
  • (Optional) Someone to proofread the provided instructions (this part I could help with).

@dune73
Copy link
Member

dune73 commented Mar 27, 2023

I could not agree more. I've had this conversation with customers repeatedly for many, many years.

My current work on dashboards brings me closer to his, but it's the essential part that is missing. Still miles away from this central piece.

@jcchavezs
Copy link

Shall we start a google doc on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants