Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Check the ModSecurity Log in DirectAdmin

This guide shows how to read the ModSecurity log. It helps you see why a visitor or a form was blocked on your site.

DirectAdmin2 min read7 steps2 screenshots

What is ModSecurity?

ModSecurity is a web firewall. A firewall is like a guard at the door. It checks each request to your site and blocks the ones that look like an attack. Sometimes it blocks a harmless request by mistake. This is called a false alarm. You may see a "403 Forbidden" error when it happens.

The log is a diary. It records each block, with the time, the visitor's IP address and the rule that fired.

Where is the log?

Where you can read it depends on your server and access level. Ask Hostvento support whether ModSecurity is turned on for your plan.

Steps for a user in the panel

  1. Log in to DirectAdmin.
  2. Look for ModSecurity in the menu. It may sit under Extra Features or Security.
  3. If you do not see it, try Site Summary / Statistics / Logs. Open the error log there.
  4. Look for lines with the word ModSecurity.

Steps for the admin on a VPS or dedicated server

This needs root access. Connect over SSH, which is a safe way to type commands on a server.

  1. Log in to your server as root.
  2. Show the last lines of the log:
    Screenshot: Show the last lines of the log:
tail -n 50 /var/log/httpd/modsec_audit.log

This prints the last 50 lines of the ModSecurity audit log. The path may differ on your server, for example on Nginx or OpenLiteSpeed setups. Ask support if the file is missing.

  1. Search for one visitor's IP address:
grep "203.0.113.5" /var/log/httpd/modsec_audit.log

Replace the example number with the real IP address. This shows every line that holds it.

How to read an entry

  • Time tells you when it happened.
  • Client IP shows who sent the request.
  • Rule id is a number for the rule that blocked it.
    Screenshot: Rule id is a number for the rule that blocked it.
  • Message explains what the rule found.

If a real action was blocked

Note the rule id and the time. Open a ticket at https://secure.hostvento.com/submitticket.php with these details. Do not turn ModSecurity off completely, because it protects your site.

Tip: Time and the rule id are the two details support needs most.

Quick recap

  • ModSecurity is a firewall that can block requests.
  • Its log records every block.
  • Look for it in the panel, or on the server over SSH.
  • Read the time, IP and rule id.
  • Send those to support if a good action was blocked.