Public operations guide

Configure, verify and manage Sentinel with clear steps.

From linking a server to protecting WordPress: requirements, modes, procedures and diagnostic commands in a guide designed for day-to-day operations.

Server agentWordPress SecurityUpdated 8 September 2026
01

First observe

Install and collect real traffic before making active rules that may interrupt legitimate requests.

02

Protect access

Always add management addresses to the allowlists and retain an alternative way to access the machine.

03

Verify every change

Check status, connectivity, logs and events after installations, updates and policy changes.

01

Before you start

Requirements and preparation

Before installation, check the system requirements on the Compatibility. You need administrative privileges, access to system repositories and outgoing connectivity to Sentinel services. Each agent must use the credential generated for its server record.

Administrative accessA root account or sudo access, plus a second access channel in case of a firewall error.
ConnectivityHTTPS for repositories and APIs, plus an encrypted agent channel to the endpoint shown by the panel.
Machine identityStable hostname and synchronized clock to associate events and certificates properly.
AllowlistKnown IPs or administrative networks before activating automatic blocks on SSH and WAF.
02

Linux Agent

Installation and first connection

  1. 1
    Create record

    In the panel, open Servers, select “Add server” and enter the required details.

  2. 2
    Copy the generated command

    Use the command shown for that server: it contains a dedicated credential and the correct endpoint.

  3. 3
    Run it on the machine

    Start the command with administrative privileges. Do not publish the API key, include it in logs or reuse it on another server.

  4. 4
    Check the heartbeat

    The record should come online and show a consistent hostname, IP address, version and last connection time.

The agent gRPC endpoint uses the format host:port, without https://. Always copy the value produced by the panel; if you enter it manually, do not turn it into a web URL.

Verify after installation
sudo sentinel-agent --check
sudo systemctl status sentinel-agent --no-pager
sudo journalctl -u sentinel-agent -n 50 --no-pager
03

Local settings

Agent configuration

The main configuration is located in /etc/sentinel/agent.yaml. The file also contains credentials and must remain readable only by administrators. Before editing it, create a backup, preserve the YAML indentation and validate the result with --check.

Minimal example — demonstration values
agent:
  server_url: "sentinel.gtechgroup.it:9090"
  api_key: "<PANEL_GENERATED_API_KEY>"

tls:
  enabled: true
  skip_verify: false

blocker:
  backend: "auto"
  chain: "SENTINEL"
  whitelist_defaults: true
  whitelist_entries:
    - "<ADMIN_IP_OR_NETWORK>"
/etc/sentinel/agent.yamlAgent configuration and credential.
/var/lib/sentinel/Operational status and local data managed by the package.
journalctl -u sentinel-agentService logs and the reason for any errors.
SENTINELSeparate firewall chain used to make Sentinel rules traceable.
04

Web protection

WAF modes and transition to blocking

The WAF protects only traffic that is actually routed through its listener. Enabling the module in the agent does not by itself change the Nginx, Apache or hosting-panel traffic path.

Observe

Detect without blocking

It identifies rules that would trigger on real traffic. This is the recommended mode for initial deployment and after significant site changes.

  • Collect a representative sample.
  • Analyse false positives and critical paths.
  • Define narrowly scoped, documented exceptions.
Block

Stop hostile requests

Rejects a request as defined by the policy when it exceeds active thresholds or matches blocking rules.

  • Enable it per domain.
  • Monitor 403 errors and conversions.
  • Keep an immediate rollback plan.
05

Sentinel Security

Connect and configure WordPress

The plugin adds a protection layer inside WordPress and sends inventory, status and security events to the panel. It does not replace updates, backups or server hardening; when the edge WAF is available, the two layers operate at different points.

  1. 1
    Register the domain

    In the WordPress section of the panel enter the exact public URL of the site.

  2. 2
    Generate the token

    Use the one-time token only on the domain for which it was created.

  3. 3
    Install the package

    Download the ZIP available in the panel, upload it in WordPress and activate Sentinel Security.

  4. 4
    Complete the link

    Open Sentinel from the WordPress side menu, enter the panel URL and token, then confirm that the site is connected.

  5. 5
    Leave Observe initially

    Review charts, events and compatibility before increasing the protection level.

06

File checks

Malware scanning and integrity

The scanner looks for known indicators and suspicious patterns; the File Integrity Monitoring highlights changes to the monitored files. A result is a signal to verify, not automatic proof that a file is malicious.

Quick scanMore frequent monitoring of priority areas and key indicators.
Full scanA broader analysis that should be planned around disk capacity, CPU load and content size.
IntegrityCompares file state to highlight unexpected or unauthorised changes.
Contextualised resultReview the path, reason, date and hash before choosing a corrective action.

Before a full scan check available space, load and maintenance windows. On WordPress sites you can start scanning from the plugin page or from the site detail in the panel when the link is active.

07

Controlled response

Quarantine and restoration

WordPress quarantine isolates a suspicious file in an encrypted, reversible form. The scanner does not delete suspicious files automatically: an administrator must confirm the action after reviewing the context.

1ReviewCheck path, reason and origin of the change.
2Back upMake sure there is a recent and verifiable backup.
3IsolateQuarantine only the confirmed file.
4VerifyCheck the site, logs and recovery path.
08

Versions and rollouts

Updating the agent and plugin

Server agent

The panel identifies outdated agents and can request an update when the installed version supports managed updates. If the remote command is not executed, the server details page shows the manual procedure to be performed directly on the machine.

Manual update of the agent only
sudo apt-get update
sudo apt-get install --only-upgrade sentinel-agent \
  -o Dpkg::Options::=--force-confold
sudo systemctl restart sentinel-agent
sudo sentinel-agent --check

WordPress Plugin

WordPress queries the Sentinel API for availability, version, package URL and checksum SHA-256. The update is only applied if the downloaded package matches the published checksum. After the update, check the version, connection, heartbeat and events.

09

Technical verification

Essential diagnostics

Full checkValidates configuration and connectivity without starting a second instance.
sudo sentinel-agent --check
Installed versionCompare it with the one indicated in the server detail.
sentinel-agent --version
Service statusIt should be active (running), without continuous restarts.
sudo systemctl status sentinel-agent --no-pager
Recent logsLook for errors after the latest start, not historical messages that have already been resolved.
sudo journalctl -u sentinel-agent -n 100 --no-pager
10

Troubleshooting

Common issues and first checks

SymptomCheckSafe action
Server offline in the panelService, DNS, system clock, endpoint host:port, TLS and API key.Run --check; do not disable TLS verification to bypass error.
Watcher SSH does not startThe configured authentication log source and its availability on that distribution.Use the updated installer or configure a supported source; do not create placeholder log files.
No WAF eventssDoes domain traffic actually pass through the WAF listener?Check the proxy upstream in Observe before activating Block.
Legitimate request blockedRule, path, parameter, timestamp and correlation ID.Return temporarily to Observe and create the most specific exception possible.
Agent update does not startVersion, connection, APT repository and job logs.Use the manual command provided by the panel directly on the server.
Invalid plugin checksumThe version offered, cache state and hash published by the API.Do not force the installation: download it again only after the package has been corrected.
Risk of SSH blockingAllowlist Sentinel, possible Fail2Ban and administrative sessions.Add management networks to both systems first, then verify access from a separate session.

Do you need a procedure that fits your infrastructure?

We check system, web server, hosting panel, traffic flow and administrative access before activation.