A parser that matches is not automatically safe to block on
Custom logs can contain attacker-controlled fields, inconsistent formats or source addresses that represent proxies rather than clients. First confirm what each field actually means.
Build a baseline
Run the monitor without blocking long enough to see normal failures, service retries, maintenance behavior and legitimate administrative mistakes. This gives you evidence for a sensible threshold.
Test known bad and known good events
Use controlled examples to confirm that failures are classified as failures, successful logins are recognized when supported, usernames are extracted correctly and source IPs correspond to real clients.
Enable enforcement gradually
Start with an alert threshold, then temporary blocking, then longer/repeat-offender behavior if the evidence supports it. Avoid jumping straight to permanent blocks on a new parser.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Scantide Guard for Windows ServerEach monitor can inherit the global Guard policy or use its own alert threshold, block threshold, time window, block duration, immediate-block behavior and notification settings.
Current Scantide source: Custom Security Log Monitoring & Automatic IP BlockingYes. A custom monitor can classify successful authentication evidence so Guard can use it for trusted-host or safe-list learning rather than blocking.
Current Scantide source: Scantide Guard for LinuxEvents from Custom Monitors feed the same deterministic Guard decision model and local firewall enforcement used by the built-in SSH and web collectors.
Current Scantide source: Scantide Guard Product & Server Security GuidesDetect repeated SSH login failures and automatically block hostile IP addresses on Linux with Scantide Guard and local firewall enforcement.
Current Scantide source: Brute Force Protection for Windows & Linux ServersScantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.
Field experience from the archive
Practical review checklist
- Each monitor can inherit the global Guard policy or use its own alert threshold, block threshold, time window, block duration, immediate-block behavior and notification settings.
- Events from Custom Monitors feed the same deterministic Guard decision model and local firewall enforcement used by the built-in SSH and web collectors.
- Detect repeated SSH login failures and automatically block hostile IP addresses on Linux with Scantide Guard and local firewall enforcement.
- Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action.
- Enable logging of login failures, access failures to operating system events etc.