Hserver Monitoring: Logs & Security · advanced
Authelia Authentication Failures Need Context, Not Panic
A two-factor login system naturally records failed credentials, expired sessions and rejected access, so any single failure is not automatically an attack.
A two-factor login system naturally records failed credentials, expired sessions and rejected access, so any single failure is not automatically an attack. I ended up treating Authelia authentication-failure logs and burst counts as the useful observation point rather than relying on a generic service-up indicator. Security monitoring becomes useful when failures are grouped by time, endpoint and surrounding successful activity instead of treated as isolated critical events.
This is a good example of contextual authentication monitoring. The purpose is to reduce ambiguity during an incident: a signal should tell me which layer to inspect next, not simply confirm that something somewhere looks unusual.
For production I use the following guardrail: Alert on abnormal bursts, preserve request context without exposing secrets, and compare failures with Cloudflare edge events and operator activity. The same rule keeps the dashboard useful when the system grows and more targets are added.
The implementation is traceable to b65d5d4 in the hserver repository. That commit is the concrete reference for the collector, alert, dashboard, or runtime change behind this article.