When a visitor, a client or your own office gets a 403 on one page of a site hosted on your DirectAdmin server, ModSecurity is often the reason. This guide shows how to confirm it on an AlmaLinux VPS running DirectAdmin: where the logs are, how to search them by IP address or domain, and how to read the rule that fired.
On a DirectAdmin server, ModSecurity is configured in /etc/httpd/conf/extra/httpd-modsecurity.conf and writes its audit log to /var/log/httpd/modsec_audit.log by default. Search that log for the client's IP address or domain with grep, then read the rule ID and message in the matched entry. Fix a false positive with a narrow exception, not by switching ModSecurity off. On Domain India shared hosting you can't do any of this yourself; open a ticket instead.
This page covers the DirectAdmin-specific steps. For how ModSecurity works, its phases, limits and tuning, read Comprehensive guide to ModSecurity: logs, configuration and important limits.
1. Who this guide is for
These steps need root access to a server running DirectAdmin, such as your own VPS. They do not apply to Domain India shared hosting: there, ModSecurity is managed server-wide by us and customers can't read the server logs or change rules.
If you are on shared hosting and a security rule blocks you, open a ticket with the full URL, the exact time and your public IP address, and we will check the log for you.
2. Find the ModSecurity files on DirectAdmin
DirectAdmin builds Apache and ModSecurity through CustomBuild. On a DirectAdmin server we checked in September 2026 (CloudLinux 8, Apache with security2_module), the layout was:
| File or folder | What it holds |
|---|---|
/etc/httpd/conf/extra/httpd-modsecurity.conf | Main ModSecurity settings, including SecAuditLog |
/var/log/httpd/modsec_audit.log | The audit log: full details of each matched request |
/var/log/httpd/modsec_debug.log | The debug log, if debug logging is on |
/var/log/httpd/error_log | Apache's main error log, with one-line ModSecurity messages |
/var/log/httpd/domains/ | Per-domain access and error logs |
/usr/local/directadmin/custombuild/custom/modsecurity/ | Your own rules and overrides, kept across rebuilds |
Your server may differ. Confirm the log path before you search:
grep -iE '^\s*SecAuditLog\b|^\s*SecAuditEngine\b' /etc/httpd/conf/extra/httpd-modsecurity.confSecAuditEngine RelevantOnly is the usual setting: only requests that matched a rule or returned an error are written to the audit log.
3. Search the log by IP address or domain
Connect over SSH as root (or a sudo user), then:
- Check that ModSecurity is loaded. `httpd -Mgrep -i security
should printsecurity2_module`. - Look at the newest entries.
tail -n 50 /var/log/httpd/modsec_audit.log - Search by the client's IP address.
grep -n '203.0.113.25' /var/log/httpd/modsec_audit.log - Search by domain.
grep -n 'Host: example.com' /var/log/httpd/modsec_audit.log - Include rotated logs.Older days are rotated into dated files, so search them too:
grep -l '203.0.113.25' /var/log/httpd/modsec_audit.log*
The quickest summary comes from the error log, which has one line per match:
# Matches for one IP, with the rule ID and message
grep 'ModSecurity' /var/log/httpd/error_log | grep '203.0.113.25' | tail -n 20
# Which rules fire most often for one domain
grep 'ModSecurity' /var/log/httpd/domains/example.com.error.log \
| grep -o 'id "[0-9]*"' | sort | uniq -c | sort -rn | headReplace the IP address and domain with your own. Finding an IP in the log means ModSecurity matched one of its requests, not necessarily that it blocked it. Check the action in the entry.
4. Read the entry
A matched request in the error log looks like this (shortened):
ModSecurity: Access denied with code 403 (phase 2). Matched phrase "union select"
at ARGS:q. [id "942100"] [msg "SQL Injection Attack Detected"]
[hostname "example.com"] [uri "/search"] [unique_id "ZxY..."]The parts that matter:
- Access denied with code 403 means it was blocked. A line without "denied" was only logged.
- id is the rule ID. You need it for any exception.
- msg is the reason in words.
- ARGS:q, or another target, shows which field of the request triggered the rule.
- unique_id lets you pull the full request from the audit log:
grep -A 40 'ZxY...' /var/log/httpd/modsec_audit.log. The H section of that entry lists every rule that matched.
Note that the IP may not be the one blocked. ModSecurity blocks requests, so the same visitor can load most pages and fail only on one form. If the whole site times out for one IP, look at the server firewall instead; see How you can identify if CSF has blacklisted your IP.
5. Fix a false positive safely
If the request was legitimate, add the smallest exception that solves it. Don't edit the files CustomBuild generates in /etc/httpd/conf/extra/, because a rebuild overwrites them. Put overrides where DirectAdmin keeps custom configuration, under /usr/local/directadmin/custombuild/custom/modsecurity/, and check DirectAdmin's documentation for your version on how that folder is included.
# Turn off one rule for one path only
<LocationMatch "^/search">
SecRuleRemoveById 942100
</LocationMatch>
# Or keep the rule but stop it checking one field
SecRuleUpdateTargetById 942100 "!ARGS:q"If the rules come from Imunify360 or another commercial ruleset, use that product's own interface to disable a rule, so its updates don't undo your change.
6. Apply the change
Test the configuration first, then reload Apache. A reload keeps current visitors connected; a failed configuration test tells you before anything breaks.
apachectl configtest && systemctl reload httpdIf you changed files through CustomBuild, rebuild the configuration with its own tool (for example ./build rewrite_confs from /usr/local/directadmin/custombuild) and then reload. Repeat the request that was blocked and check the log again.
7. Where Domain India fits
- Shared hosting: ModSecurity is managed for you on every server. You don't search logs; you send us the URL, time and IP by ticket.
- VPS: a Domain India VPS is self-managed with full root access. DirectAdmin is one of the control panel options at checkout, and cPanel is not offered on a VPS. ModSecurity, its logs and its rules are then yours to run. The card shows the live list price, excluding 18% GST.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Where is the ModSecurity log on a DirectAdmin server?
By default DirectAdmin's CustomBuild sets SecAuditLog to /var/log/httpd/modsec_audit.log, configured in /etc/httpd/conf/extra/httpd-modsecurity.conf. One-line summaries of each match also appear in /var/log/httpd/error_log and in the per-domain error logs under /var/log/httpd/domains/.
If an IP appears in the ModSecurity log, is it blocked?
Not necessarily. It means one of its requests matched a rule. The entry says "Access denied with code 403" when the request was blocked; other entries were only logged.
How do I restart Apache after changing ModSecurity rules on AlmaLinux?
Run apachectl configtest first, then systemctl reload httpd. The service is called httpd on AlmaLinux and other RHEL-based systems.
Should I switch ModSecurity off to fix a false positive?
No. Remove or narrow the one rule that fired, for one path or one field, using its rule ID from the log. Switching the engine off removes protection for every site on the server.
Can I check ModSecurity logs on Domain India shared hosting?
No. On shared hosting, ModSecurity is managed server-wide by Domain India and the logs are not available to customers. Open a ticket with the full URL, the exact time and your public IP address, and support will check which rule fired.
Why did my edit to httpd-modsecurity.conf disappear?
DirectAdmin's CustomBuild regenerates the files in /etc/httpd/conf/extra/ when it rebuilds Apache. Keep your own rules under /usr/local/directadmin/custombuild/custom/modsecurity/ so they survive.
Ready to take control of your own server? Compare VPS plans, or if a security rule is blocking your shared hosting site, open a ticket with the URL, time and your IP address.
Send us the URL, the time and your IP address, and we will check the rule that fired.
Open a ticket