Monitoring failed login attempts helps you catch attacks in progress. Learn how to set up alerts and reviews for cPanel login failures.
Why Visibility Matters
Many security breaches go unnoticed for weeks because no one is watching login activity. Enabling failure monitoring gives you real-time visibility into attack attempts, allowing you to respond before a determined attacker succeeds.
What to Monitor
- Failed cPanel and WHM login attempts
- Failed FTP and email authentication attempts
- Repeated attempts from the same IP address or IP range
- Login attempts targeting non-existent usernames, which often indicate automated scanning
How to Enable Monitoring in WHM
- Ensure cPHulk Brute Force Protection is enabled, as it logs failed attempts by default.
- Navigate to Security Center > cPHulk Brute Force Protection and enable email notifications for blocked attempts.
- Review WHM’s Server Status > Login Attempts Log periodically for patterns.
- If using CSF, enable Login Failure Daemon (LFD) alerts, which notify you of suspicious authentication activity across multiple services in real time.
Setting Up Meaningful Alerts
- Configure alerts to go to an email address or channel that’s actually monitored regularly, not a forgotten inbox.
- Set thresholds that balance timely alerts against notification fatigue — too many alerts leads to important ones being ignored.
- Consider integrating logs with a centralized monitoring tool if managing multiple servers.
Turning Monitoring Into Action
Monitoring alone isn’t protection — it’s the trigger for a response plan. Decide in advance what steps you’ll take when an alert fires: blocking an IP, rotating a password, or investigating further.
Login failure monitoring transforms security from a “set and forget” checklist item into an active, responsive practice that catches attacks as they happen.