What is a WAF log?
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A log is a diary. Each time the WAF blocks or flags a visit, it writes a line in the diary.
Reading it helps you see which attacks come, find good visitors that were blocked by mistake, and spot the same bad address coming back many times.
Where to find the logs
- WHM (the server owner's panel; needs root access): search
ModSecurity Tools, then open the Hits List. - Plesk: open Tools & Settings, then Web Application Firewall (ModSecurity), then the Logs tab.
- cPanel: some servers show a hits list or error logs. Look under Metrics for Errors.
- On the server: the file is often
/var/log/modsec_audit.logor inside the Apache logs folder.
Locations differ between servers. Ask Hostvento support if you cannot find yours.
Steps to read a log
- Open the log in your panel or connect to the server with SSH.
- To see the latest lines on the server, run:
tail -n 50 /var/log/modsec_audit.log
This shows the last 50 lines of the log file.
- Find these parts in each entry:
- Time: when it happened.
- IP address: who sent the request.
- Request: the page or address they asked for.
- Rule ID and message: which rule fired and why.
- Action: blocked, or only logged.
- To search for one rule, run:
grep "id \"942100\"" /var/log/modsec_audit.log
This prints only the lines that mention rule 942100. Use the ID you care about.
What to look for
- One IP address with hundreds of hits. It may be a bot. Block that IP in your firewall.
- Many hits on
wp-login.php. Someone is guessing passwords. - A good action blocked, such as saving a post. Note the rule ID and add an exception.
Tip: Check the logs once a week. Also check right after you install a new plugin or turn on new rules.
Tip: Logs can grow very large. Do not delete them without a plan. Ask support about log rotation, which archives old logs automatically.
Need help? Open a support ticket.
Quick recap
- A WAF log records blocked and flagged requests.
- Find it in WHM, Plesk or on the server.
- Read time, IP, request, rule ID and action.
- Block repeat offenders and fix false positives.
- Review the log every week.