High RAM Usage with Concurrent Logging Mode in ModSecurity
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
調査の方向性
まず、RAMと監査ログの増加を監視しながら、ModSecurity 3.0.13、Nginx 1.27.1、SecAuditLogType Concurrent、および SecAuditLogStorageDir /var/log/modsec/audit を使用して報告された事象を再現します。ログを消去する前後でメモリ使用量を比較します。原因が特定され、継続的なトラフィックおよび低トラフィックの間もメモリが安定していれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Description
I am experiencing an issue where my application consumes a high amount of RAM when using the Concurrent Logging mode in ModSecurity. The memory usage increases gradually over time and does not decrease, even after periods of low activity, until I cleaned the logs.
Environment
- ModSecurity Version: 3.0.13
- Web Server: Nginx 1.27.1
- Application Details: a PHP-based web app
- Concurrent Logging Configuration:
SecAuditLogType Concurrent
SecAuditLogStorageDir /var/log/modsec/audit
Steps to Reproduce
- Enable Concurrent Logging mode in ModSecurity configuration.
- Run the application under normal traffic.
- Monitor RAM usage over time (e.g., using
toporhtopor metric Grafana). - Observe that RAM usage increases continuously without dropping.
- Clear the log in /var/log/modsec directory and watch the RAM decrease.
Expected Behavior
- RAM usage should remain stable or decrease during low traffic periods.
Actual Behavior
- RAM usage increases gradually and does not decrease, leading to potential memory exhaustion.
Additional Information
Ram increased from 300MiB to 4GiB in almost 30 days on nginx:
Ram usage reduced after cleaning up logs:
Request
I would appreciate any insights or solutions to mitigate this memory consumption issue. Is there a recommended configuration for Concurrent Logging to prevent memory leaks, or is this a bug?
Thank you for your help!
- 主要言語
- C++
- スター
- 9.8k
- フォーク
- 1.8k
- 平均マージ
- 2時間 46分
- マージ済み PR(30日)
- 1
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
owasp-modsecurity/ModSecurity のほかの issue
-
2.x Platform - IIS
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
owasp-modsecurity/ModSecurity#3623 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
owasp-modsecurity/ModSecurity#3621 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
owasp-modsecurity/ModSecurity#3619 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
2.x Platform - IIS
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
owasp-modsecurity/ModSecurity#3612 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
3.x
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
owasp-modsecurity/ModSecurity#3580 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
owasp-modsecurity/ModSecurity の issue をすべて見る
似ている issue
-
Unconfirmed bug
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
luanti-org/luanti#17605 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
area: config area: firmware priority: P2 - medium size: S type: bug
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
Mizithra/ActiveTerrain#16 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
grumpycoders/pcsx-redux#2171 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
bytedance/trae-agent#524 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信