Custom Security Log Monitoring
Not every application deserves a hard-coded collector. Guard Custom Monitors let administrators teach Guard how a trusted event channel or log file represents authentication failures, successful logins and source IP evidence.
Windows Event channel monitors
Supported as part of the Guard monitoring, policy or enforcement workflow.
Single log file or rolling-directory patterns
Supported as part of the Guard monitoring, policy or enforcement workflow.
Recognition and IP extraction expressions
Supported as part of the Guard monitoring, policy or enforcement workflow.
Username extraction where available
Supported as part of the Guard monitoring, policy or enforcement workflow.
Failed and successful authentication classification
Supported as part of the Guard monitoring, policy or enforcement workflow.
Successful-login evidence for trusted-host learning
Supported as part of the Guard monitoring, policy or enforcement workflow.
What this Guard workflow covers
- Windows Event channel monitors
- Single log file or rolling-directory patterns
- Recognition and IP extraction expressions
- Username extraction where available
- Failed and successful authentication classification
- Successful-login evidence for trusted-host learning
- Per-monitor alert and block overrides
- Display-name based event and email reporting
- Portable/community monitor package model
Designed around observable server evidence
Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.
The result is intended to be understandable by an administrator: which source IP was seen, which collector reported it, which rule or threshold was reached, what action Guard took, and when a temporary block is due to expire.
Standalone when you need it. Centralized when you grow.
A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.
Frequently asked questions
Can Guard watch rotating logs?
Yes. Custom monitors can target a directory and filename pattern, with optional recursive handling where appropriate.
Can successful logins be used?
Yes. A custom monitor can classify successful authentication evidence so Guard can use it for trusted-host or safe-list learning rather than blocking.
Can each application have different thresholds?
Yes. The design supports per-monitor overrides so applications with different authentication behavior do not have to share one global threshold.
See Scantide Guard in context
Read the current Guard documentation, deployment notes and product status, then choose the Windows, Linux or Datacenter path that fits your environment.