# Adding modsecurity acquisitions

**URL:** <https://discourse.crowdsec.net/t/adding-modsecurity-acquisitions/592>\
**Category:** crowdsec\
**Created:** [January 26, 2022, 4:52pm UTC](https://discourse.crowdsec.net/t/adding-modsecurity-acquisitions/592 "2022-01-26T16:52:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dimmthewitted](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/dimmthewitted/32/266_2.png) [@dimmthewitted](https://discourse.crowdsec.net/u/dimmthewitted)\
**Post date:** [January 26, 2022, 4:52pm UTC](https://discourse.crowdsec.net/t/adding-modsecurity-acquisitions/592/1 "2022-01-26T16:52:46Z")

</div>

When I try to replay a modsecurity log I get an error that there are no matching patterns.

I have the modsecurity collection installed.

When I look at my acquistion list:  
cat acquis.yaml

I only see apache2 log filenames.  
I do not see: modsec\_audit.log or mod\_jk.log  
I believe these are default out of box log files.

I have the parser.

## PARSERS

## NAME 📦 STATUS VERSION LOCAL PATH

crowdsecurity/modsecurity ✔ enabled 0.9 /etc/crowdsec/parsers/s01-parse/modsecurity.yaml

Is it possible the parsers don’t have patterns for these modsecurity logs?  
Do I need to re-run my wizard.sh or manually add to the acquis.yaml ?

I wonder if there is a list of what log files / collections that there exists patterns in the parsers.

---

<div class="post-metadata">

**Author:** ![BRSS73](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/brss73/32/279_2.png) [@BRSS73](https://discourse.crowdsec.net/u/BRSS73)\
**Post date:** [January 28, 2022, 12:23pm UTC](https://discourse.crowdsec.net/t/adding-modsecurity-acquisitions/592/2 "2022-01-28T12:23:18Z")

</div>

The modsecurity parser use the Apache error log file.

Add this to your acquis.yaml file (adjust the error log according your configuration):

```auto
filenames:
  - /var/log/apache2/error.log
labels:
  type: modsecurity
---

```
