# New version of OWASP CRS breaks the Modsecurity parser

**URL:** <https://discourse.crowdsec.net/t/new-version-of-owasp-crs-breaks-the-modsecurity-parser/1692>\
**Category:** crowdsec\
**Created:** [March 9, 2024, 11:46am UTC](https://discourse.crowdsec.net/t/new-version-of-owasp-crs-breaks-the-modsecurity-parser/1692 "2024-03-09T11:46:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ne20002](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/ne20002/32/1012_2.png) [@ne20002](https://discourse.crowdsec.net/u/ne20002)\
**Post date:** [March 9, 2024, 11:46am UTC](https://discourse.crowdsec.net/t/new-version-of-owasp-crs-breaks-the-modsecurity-parser/1692/1 "2024-03-09T11:46:35Z")

</div>

**Describe the bug**  
With version 4 of [OWASP CRS](https://github.com/coreruleset) the logging information in Nginx/Apache error.log has been changed.

**To Reproduce**  
Update OWASP CRS to version 4.

**Expected behavior**  
Crowdsec should still detect relevant information.

**Additional context**  
An [issue](https://github.com/coreruleset/modsecurity-crs-docker/issues/215) has already been filed at CRS project to discuss the matter.

---

<div class="post-metadata">

**Author:** ![ne20002](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/ne20002/32/1012_2.png) [@ne20002](https://discourse.crowdsec.net/u/ne20002)\
**Post date:** [March 14, 2024, 8:47am UTC](https://discourse.crowdsec.net/t/new-version-of-owasp-crs-breaks-the-modsecurity-parser/1692/2 "2024-03-14T08:47:02Z")

</div>

So problem has been tracked down. It affects only Modsecurity3 / Nginx. With CRS 4 the blocking rules are no longer logged with a severity which makes the Crowdsec parser to ignore it.  
If Nginx error log level is set to ‘info’ the detection rule is logged to the error.log and the Crowdsec parser will detect the log entries.
