How to Configure MySQL Brute-Force Protection and Log Monitoring in RdpGuard
RdpGuard
Intrusion prevention system for your Windows Server
 

MySQL Brute-Force Protection

Protection overview

RdpGuard protects your MySQL server from dictionary-based brute-force attacks.

It monitors failed MySQL login attempts and blocks the source IP address when the number of failures reaches the configured limit.

Choose Application Event Log or MySQL General Log, depending on where your MySQL server records failed connections. RdpGuard must run on the Windows computer hosting the MySQL server.

Enable and configure MySQL brute-force protection

  1. Open RdpGuard Dashboard and click MySQL under Monitored protocols.

    MySQL button in the Monitored protocols section of RdpGuard Dashboard
    Click MySQL to open its protection settings.
  2. Select Enable MySQL protection, choose a monitoring method and configure it as described below. Then click Save.

    MySQL Settings with Application Event Log selected and general-log options disabled
    MySQL protection using the Windows Application log.

Monitoring method

Monitoring via Application Event Log

This is the default method and is recommended when MySQL writes failed login attempts to the Windows Application log. It avoids reading the general query log and does not require a configuration-file or log-file path in RdpGuard.

In MySQL 8.0, Windows Event Log output must be enabled explicitly. See the MySQL instructions for MySQL 8.0 or MySQL 8.4.

In Event Viewer, Windows Logs, Application, check that failed connections produce events with source MySQL, event ID 100 and a message containing Access denied for user. These are the events RdpGuard monitors. Selecting this method does not enable MySQL logging automatically.

Multiple MySQL instances on the same computer can be monitored through the shared Application log, provided each instance writes these events.

Monitoring via MySQL General Log

Use MySQL General Log when failed connections are recorded in a general log file instead of the Windows Application log. This method may be slower on heavily loaded servers and monitors one general log file.

Enable MySQL general logging with log-output=FILE, then select MySQL General Log in RdpGuard. Logging only to a MySQL table is not sufficient.

MySQL Settings with MySQL General Log selected and automatic discovery enabled
MySQL General Log monitoring with automatic file discovery.

Automatically detect config file location

When automatic general-log discovery is enabled, RdpGuard reads the log location from my.ini or my.cnf. It searches for the configuration file under %PROGRAMDATA%\MySQL.

If the file is elsewhere or several configuration files are found, clear Automatically detect config file location and select the configuration file for the MySQL instance you want to protect.

Automatically detect general log file location

RdpGuard reads general_log_file from the selected configuration file. A relative log path is resolved using datadir.

If the log cannot be found automatically, clear Automatically detect general log file location and select the existing general log file. When you specify the log file directly, RdpGuard does not need the configuration-file path. Click Save to apply the settings.

Check engine status

Open View, Show event log in RdpGuard Dashboard and check for MySQL monitoring errors. If you changed MySQL logging outside RdpGuard, restart the RdpGuard service via Tools, RdpGuard Service, Restart to reload the log settings.

  • Application Event Log: check that failed connections appear in the Windows Application log with the source, event ID and message described above. If they do not, configure MySQL event logging or use MySQL General Log.
  • MySQL General Log: check that logging to a file is enabled, the file exists and the RdpGuard service can read it. Specify the file path manually if automatic discovery fails.

See also

How to Enable the MySQL General Query Log on Windows

RdpGuard 10.3.9 Free Trial

RdpGuard protects:

Our customers say

"This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques

"Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson

"Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford

"Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch

"Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan

"It's a great product - really stopping those RDP attackers :-)" - Dave, UK

"First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes

Our Other Products
Copyright © 2012-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.