Thank you for the questions.
Hi, is it safe to use the core rules along side the ASL ones;
Sure, you can use the OWASP rules with ours, you can use anyones rules with ours. Rules don't conflict per se.
However, if you use the OWASP rules you should know that you will need to heavily tune them for your system and you should expect a high amount of false positives with those rules, they are not tuned and there is no built in logic for known applications.
IMHO, the OWASP rules are really for security researchers, not production hosting environments so I wouldnt recommend you use them unless you have lots of time to babysit them and the expertise to know what you are doing with them.
or are the core ones integrated into the ASL ones ?
Not necessary, the ASL rules already cover everything the OWASP rules do and then some. We were writing modsecurity rules years before the first OWASP rule was published.