First observe
Install and collect real traffic before making active rules that may interrupt legitimate requests.
Public operations guide
From linking a server to protecting WordPress: requirements, modes, procedures and diagnostic commands in a guide designed for day-to-day operations.
Install and collect real traffic before making active rules that may interrupt legitimate requests.
Always add management addresses to the allowlists and retain an alternative way to access the machine.
Check status, connectivity, logs and events after installations, updates and policy changes.
Before you start
Before installation, check the system requirements on the Compatibility. You need administrative privileges, access to system repositories and outgoing connectivity to Sentinel services. Each agent must use the credential generated for its server record.
Linux Agent
In the panel, open Servers, select “Add server” and enter the required details.
Use the command shown for that server: it contains a dedicated credential and the correct endpoint.
Start the command with administrative privileges. Do not publish the API key, include it in logs or reuse it on another server.
The record should come online and show a consistent hostname, IP address, version and last connection time.
The agent gRPC endpoint uses the format host:port, without https://. Always copy the value produced by the panel; if you enter it manually, do not turn it into a web URL.
sudo sentinel-agent --check
sudo systemctl status sentinel-agent --no-pager
sudo journalctl -u sentinel-agent -n 50 --no-pager
Local settings
The main configuration is located in /etc/sentinel/agent.yaml. The file also contains credentials and must remain readable only by administrators. Before editing it, create a backup, preserve the YAML indentation and validate the result with --check.
agent:
server_url: "sentinel.gtechgroup.it:9090"
api_key: "<PANEL_GENERATED_API_KEY>"
tls:
enabled: true
skip_verify: false
blocker:
backend: "auto"
chain: "SENTINEL"
whitelist_defaults: true
whitelist_entries:
- "<ADMIN_IP_OR_NETWORK>"
/etc/sentinel/agent.yamlAgent configuration and credential./var/lib/sentinel/Operational status and local data managed by the package.journalctl -u sentinel-agentService logs and the reason for any errors.SENTINELSeparate firewall chain used to make Sentinel rules traceable.Web protection
The WAF protects only traffic that is actually routed through its listener. Enabling the module in the agent does not by itself change the Nginx, Apache or hosting-panel traffic path.
It identifies rules that would trigger on real traffic. This is the recommended mode for initial deployment and after significant site changes.
Rejects a request as defined by the policy when it exceeds active thresholds or matches blocking rules.
Sentinel Security
The plugin adds a protection layer inside WordPress and sends inventory, status and security events to the panel. It does not replace updates, backups or server hardening; when the edge WAF is available, the two layers operate at different points.
In the WordPress section of the panel enter the exact public URL of the site.
Use the one-time token only on the domain for which it was created.
Download the ZIP available in the panel, upload it in WordPress and activate Sentinel Security.
Open Sentinel from the WordPress side menu, enter the panel URL and token, then confirm that the site is connected.
Review charts, events and compatibility before increasing the protection level.
Local WAF, Login Shield, antispam, scanning, integrity checks, quarantine, reports and centralised management.
File checks
The scanner looks for known indicators and suspicious patterns; the File Integrity Monitoring highlights changes to the monitored files. A result is a signal to verify, not automatic proof that a file is malicious.
Before a full scan check available space, load and maintenance windows. On WordPress sites you can start scanning from the plugin page or from the site detail in the panel when the link is active.
Controlled response
WordPress quarantine isolates a suspicious file in an encrypted, reversible form. The scanner does not delete suspicious files automatically: an administrator must confirm the action after reviewing the context.
Versions and rollouts
The panel identifies outdated agents and can request an update when the installed version supports managed updates. If the remote command is not executed, the server details page shows the manual procedure to be performed directly on the machine.
sudo apt-get update
sudo apt-get install --only-upgrade sentinel-agent \
-o Dpkg::Options::=--force-confold
sudo systemctl restart sentinel-agent
sudo sentinel-agent --check
WordPress queries the Sentinel API for availability, version, package URL and checksum SHA-256. The update is only applied if the downloaded package matches the published checksum. After the update, check the version, connection, heartbeat and events.
Technical verification
sudo sentinel-agent --checksentinel-agent --versionsudo systemctl status sentinel-agent --no-pagersudo journalctl -u sentinel-agent -n 100 --no-pagerTroubleshooting
| Symptom | Check | Safe action |
|---|---|---|
| Server offline in the panel | Service, DNS, system clock, endpoint host:port, TLS and API key. | Run --check; do not disable TLS verification to bypass error. |
| Watcher SSH does not start | The configured authentication log source and its availability on that distribution. | Use the updated installer or configure a supported source; do not create placeholder log files. |
| No WAF eventss | Does domain traffic actually pass through the WAF listener? | Check the proxy upstream in Observe before activating Block. |
| Legitimate request blocked | Rule, path, parameter, timestamp and correlation ID. | Return temporarily to Observe and create the most specific exception possible. |
| Agent update does not start | Version, connection, APT repository and job logs. | Use the manual command provided by the panel directly on the server. |
| Invalid plugin checksum | The version offered, cache state and hash published by the API. | Do not force the installation: download it again only after the package has been corrected. |
| Risk of SSH blocking | Allowlist Sentinel, possible Fail2Ban and administrative sessions. | Add management networks to both systems first, then verify access from a separate session. |
We check system, web server, hosting panel, traffic flow and administrative access before activation.