內容簡介
Simula Security Telemetry for Wordfence 外掛可將 Wordfence 的安全性遙測數據以兩種形式匯出,適用於已使用 Wordfence 和 Prometheus 基礎設施的 WordPress 網站,提供更安全的數據管理與監控。
【主要功能】
• 匯出 Prometheus 指標供 node_exporter 使用
• 本地事件日誌記錄被阻擋的請求
• 支援可配置的 Cron 收集間隔
• 提供 IP 和使用者的鎖定計數
• 匯出 Grafana 儀表板和範例警報規則
• 事件隱私控制選項
外掛標籤
開發者團隊
② 後台搜尋「Simula Security Telemetry for Wordfence」→ 直接安裝(推薦)
原文外掛簡介
Simula Security Telemetry for Wordfence exports Wordfence security telemetry in two forms:
Prometheus metrics for the node_exporter textfile collector that can be scraped by Prometheus
A local incident log containing blocked Wordfence requests that can be shipped with Grafana Alloy
This plugin is intended for WordPress sites that already use Wordfence and Prometheus-based infrastructure. Instead of exposing a public metrics endpoint from WordPress, the plugin writes local files that node_exporter and log-based tooling can consume.
By default, the plugin runs a fast collector every 15 minutes and a slow collector hourly using WP-Cron. It supports:
Exporter health and plugin metadata metrics
Configurable cron interval
Separate fast and slow collector intervals
Per-metric-family enable or disable controls
Aggregate firewall block counts derived from locally stored Wordfence block-log data
Blocked hit-row counters and recent activity windows
Blocked event counts by HTTP status code over the last 24 hours
Failed login, rate-limited, and brute-force activity windows
Current lockout counts for IPs and users
Wordfence two-factor status and protected user counts
Scan issue counts by severity
Malware, file change, and vulnerable component findings
Top blocked attack sources by country and normalized IP range
Incident log export for newly observed blocked requests
Incident privacy controls for IPs, URLs, referers, user agents, and internal traffic
Manual export and incident cursor reset from the admin UI
Current exporter and incident state visibility in the admin UI
Optional JSON Lines incident output
WP-CLI exports for system cron
Source freshness and WordPress/Wordfence posture metrics
A ready-to-import Grafana dashboard and sample Prometheus alert rules
The plugin exposes two distinct Wordfence blocking measurements. blocked_hit_rows_* counts retained hit/live-traffic records matching a blocked-request predicate. firewall_blocks_* derives aggregate block counts from locally stored Wordfence block-log data and groups them into bounded categories and reporting windows. The values are not expected to be equal because the two metric families use different sources, units, retention behavior, and categorization.
The legacy blocked_events_* names are deprecated aliases for the hit/live-traffic row model. They are still emitted for compatibility, but they represent retained blocked hit rows rather than the aggregate block-log data exposed through firewall_blocks_*.
Blocked hit rows are currently identified from the Wordfence hits table where:
action matches blocked:*
or the HTTP status code is 403 or 503
The plugin includes an admin settings screen under Settings > Security Telemetry, where you can:
Enable or disable the exporter master switch
Choose the export cron interval
Choose the slow collector interval
Set the .prom output path
Set a custom metric prefix
Set a custom site label
Enable or disable individual metric families
Enable or disable incident log export
Set the incident log path
Choose text or JSON Lines incident output
Limit the number of incidents appended per run
Configure incident IP privacy and field-dropping filters
Add an optional retention note to emitted incident events
Trigger a manual export
Reset the incident cursor for backfill
Review current exporter and incident state
Simula Security Telemetry for Wordfence is an independent open-source project and is not affiliated with, endorsed by, sponsored by, or otherwise associated with Defiant, Inc. or Wordfence.
Wordfence and related names and marks are the property of their respective owners.
