Attacks

Hostile requests ranked by what your server answered, because a probe answered 404 is not an incident.

Attacks shows the hostile requests in your access log: what was tried, who tried it, and, most important, what your server answered. A probe answered with a 404 is your server doing its job. The few answered with a page or a redirect are the ones worth your time, so they come first.

Loghound is not a firewall and blocked none of this

It reads the log after the fact. Every request here was already served or refused by your web server.

01 · The eight pages of the view
  1. What the server answered: matched requests counted by status class (answered 2xx, redirected 3xx, refused 4xx, server error 5xx), never added together. Also distinct addresses, how many requests were checked and how many were never checked.
  2. What is being tried: grouped by pattern, not by exact request (every probe is different), ordered by how many attempts the server answered.
  3. The requests the server answered: the individual matched requests that got a 2xx or 3xx, up to 200 of them. Fetch one yourself and look.
  4. Who is doing it: addresses and networks behind the matched requests, ordered by how many were answered.
  5. Crawlers that are not what they say: visits whose User-Agent named a crawler, split into claim verified, reverse DNS check failed, and answering from a rented cloud machine.
  6. When: matched requests over the period with the answered ones beneath. One line rising alone is background noise; both rising together is a burst worth reading.
  7. Pattern by status class: the same patterns as a grid against the four status classes.
  8. What this page does not claim: the limits below, and for each pattern what it matches, what it misses and what it over-reports.
02 · Reading it honestly
  • A 2xx does not prove a leak. A site whose error page is served with a 200 looks exactly like one that handed a file over. Fetch the URL and check.
  • A 404 is not nothing, it is just not an incident. Every public address collects thousands of probes a day.
  • Detection runs when a request is read, so it only covers what it was there for. A request indexed before this feature existed is counted as never evaluated, not as clean.
  • The request line is all there is. An access log records the method, path and query string, never the request body.

Your own patterns join the built-in ones as Your attack pattern: Attack patterns. How a probe affects a visit’s score: Exploit probe, Refused attack and Refused probe sweep on Rules decisive alone and Rules that stack.

Analysis views

Loghound is open source and MIT licensed. Questions about the Opensolr half — the account, the indexes, the plan — go to opensolr.com/contact; questions about the software itself belong on GitHub.

Loghound Documentation