Drop your Apache or Nginx access log file into the analyzer.
Four detection algorithms run simultaneously against your log data.
Every threat scored, ranked, and explained in plain English.
| IP / Identifier | Anomaly Type | Risk Score | Severity |
|---|
Upload a log file above to begin threat analysis.
Log Sentinel detects four categories of suspicious behavior. Here's what each one means and why it matters.
A brute force attack happens when someone repeatedly tries to guess a password by sending hundreds or thousands of login attempts in a short time. They're usually automated bots cycling through common password lists.
Directory scanning is when an attacker probes your server for hidden or sensitive files — things like admin panels, configuration files, or database backups. They use automated tools that try thousands of common paths looking for anything exposed.
When the same IP repeatedly causes 500 internal server errors, it often means they're sending malformed or malicious requests designed to break your application. This can be a sign of injection attacks or attempts to find exploitable bugs.
Traffic between midnight and 6am is inherently suspicious for most applications. Legitimate users are rarely active at 3am, but automated bots and attackers often operate at night to avoid detection and reduce competition for server resources.
Every flagged event is assigned a risk score based on its threat level. Scores stack when a single IP triggers multiple anomaly types.