Sentinel protection metrics, updated every 15 minutes.
Detected attacks, enforced blocks, distinct sources, countries of origin and block duration: this report shows the protection work performed by Sentinel across the connected network. Every metric comes from real events and is consolidated automatically.
Real operational data · automatically updated every 15 minutes
Threat Pulse · Sentinel network
An immediate reading of what is happening.
Sentinel turns thousands of technical signals into clear indicators. These are not commercial estimates: every figure comes from real events and is recalculated every 15 minutes.
Operational overview
More context, not just a counter.
Time windows distinguish a recent spike from persistent activity. Source counts are deduplicated before publication.
Recent developments
Attacks detected day by day
Loading trend...
Origin and response
Where hostile activity originates and how long blocks remain active.
The country represents the geolocated technical origin, not necessarily the attacker’s actual location.
Geographical distribution
Countries with the most attacks
Podium composition...
| Country | Attacks | Blocked sources | Relative intensity |
|---|---|---|---|
| Loading the rankings... | |||
Techniques observed
Which controls are detecting and blocking the most activity.
The types describe the recorded events; the reasons explain why the sources in the protection list have been blocked.
Aggregated events
Most frequent attack types
Loading typologies...
Blocks currently active
Why sources are blocked
Loading reasons...
Protection is measured through concrete results.
Every metric comes from events actually detected and actions actually enforced: stopped attempts, blocked sources, block duration and geographic distribution. The report is designed to show security volume, effectiveness and trends; individual IP addresses are operational details and are not part of this public view.
Sources and methodology
How public data is built and controlled.
This section makes explicit origin, frequency, time windows and dataset limits, so the numbers can be interpreted correctly even outside their graphical context.
Technical sources
Aggregated events collected by Sentinel agents, log watchers, the WAF and security integrations enabled on connected systems.
Frequency
The public file is automatically rebuilt every 15 minutes. The date of the last valid update is shown at the top and included in the metadata of the dataset.
Time windows
Summaries use 24-hour, 7-day and 30-day windows. Active blocks are a snapshot taken when the dataset is generated.
Metric processing
Events are consolidated by period, technique, country and block reason. The result highlights the work performed by the protection controls and makes different time windows comparable.
How to read data
Operational metrics for assessing pressure and response.
Technical traffic origin
Country distribution identifies where more hostile activity originates and helps tune geo-blocking, reputation and access rules.
Distinct sources
The metric groups distinct technical origins within the period, preventing repeated events from the same source from inflating the result.
Update every 15 minutes
The dataset is automatically rebuilt from scratch. If generation or metric validation fails, the latest valid snapshot remains available.
Remaining block duration
The time bands describe when the currently active blocks will expire; the permanent ones require an authorised revocation.
Do you want this visibility on your servers?
Sentinel centralises fleet events and enforces protection close to the applications.