Reference Manual:
http://sourceforge.net/apps/mediawiki/mod-security/index.php?title=Reference_Manual#SecRuleEngine

Current setting:

# Enable ModSecurity, attaching it to every transaction. Use detection
# only to start with, because that minimises the chances of post-installation
# disruption.
#
SecRuleEngine DetectionOnly


Rationale:
When first adding in ModSecurity, you want to minimize any disruptions to 
traffic until you get a handle on how your configs/rules will respond to your 
traffic.  This setting allows SecRules to trigger events but not take any 
disruptive actions.

_______________________________________________
Owasp-modsecurity-core-rule-set mailing list
[email protected]
https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set

Reply via email to