The server also defends itself outside of web traffic.

Sentinel monitors SSH access attempts and security logs, recognises repeated attempts and blocks the IP on the local firewall. The event is immediately sent to the central panel and the block can be shared with the fleet.

SSH brute-forceNginx & ApacheLocal Firewall
The signal

A source repeatedly targets logins, URLs or exposed services.

The agent reads logs on the server and counts events in the configured time window.

The Decision

After crossing the threshold, the IP is stopped locally.

The block is applied through the system's firewall without waiting for an response from an external cloud service.

Visibility

The panel retains pattern, origin and recurrence.

See which server has detected abuse and manage its duration, removal and allowlist exceptions.

Remote Access

Detect SSH brute-force attempts at source.

On Linux the agent follows the authentication log, distinguishes incorrect passwords and non-existent users and groups attempts by IP address.

01

Observe

It reads the new lines produced by SSH in real time, without sending the entire log file out of the server.

02

Count

It groups attempts by IP address in a time window and ignores local or invalid addresses.

03

Lock

At the configured threshold, it applies a temporary block on the firewall and records the event centrally.

Web server & applications

Nginx, Apache and logs from your applications.

In addition to SSH, Sentinel can monitor the error logs of Nginx and Apache. For specific applications you can define custom watchers with file path and recognition patterns.

  • Local patterns: the recognition takes place on the agent.
  • Anti-noise threshold: A single error does not automatically become a ban.
  • Contextualised event: type, IP, server and details appear in the dashboard.
Agent aggregate log in the Sentinel dashboard

Local and global block

The firewall acts immediately, the fleet learns from the event.

On Linux Sentinel uses iptables or ipset. The block is applied to the server that detected the abuse and centrally recorded; the central server can then propagate it to the other connected agents.

  • TTL or permanent: Blocks can expire automatically.
  • Tracked repeat attacks: The event history retains the number of attacks from the same IP address.
  • Priority allowlist: Corporate networks, monitoring and partners are never blocked.
Blocked IP address management in the Sentinel dashboard

Operational control

Not only automation: you can intervene from the panel.

Manual block

Enter an IP, choose the duration or make the block permanent and distribute the decision to the fleet.

Unlocking and expiration

Remove an IP from the panel or let Sentinel remove the expired blocks automatically.

Reason and source

You distinguish brute-force SSH, WAF attacks, rate-limit and manual actions, with geographic data when available.

Windows, for accesses

The Windows agent can observe authentication events and apply blocks with Windows Firewall. WAF functions and web watchers remain Linux deployment oriented.

Do you want to protect server access too?

Let's start with the logs and services that are actually exposed in your infrastructure.