Can I send ModSecurity alert log data through Syslog?
Yes. If you already have a central Syslog infrastructure setup and/or if you are using some sort of SIM application (such as LogLogic, Intellitactics, etc…) then you might want to include the short version ModSecurity alert messages that appear in the Apache error_log file. You can easily reconfigure Apache to send its error logs through Syslog onto a remote, central logging server however the data being forwarded is a very small subset of the entire transaction. It is only a warning message and not enough information to conduct proper incident response to determine if there was a false positive or if it was a legitimate attack. In order to determine this information, you need access to the ModSecurity Audit log files.