Proof that protection is working.
Analytics is the instrument panel over everything AntiLink already caught. Threats blocked over time, the risk mix, the worst domains, the repeat offenders and raid activity - read straight from your own logs. It measures. It never collects.
Dashboard only. There is no slash command, nothing to switch on, and no new tracking to consent to.
Analytics
Sanctuary Gaming - security activity
Blocked (30d)
1,484
▲ 23%vs the previous 30 days
Blocked all-time
12,940
every block ever logged here
Active days
26/30
days with at least one block
Busiest day
118
2026-07-19
Threats blocked - last 30 days
peak 118
A live look at the console. Every number is computed on the server before the page is sent.
By risk level
1,484 blocks- Critical52 (3.5%)
- High156 (10.5%)
- Medium441 (29.7%)
- Low761 (51.3%)
- Unknown74 (5%)
Risk is the level the scanner recorded at the moment it acted. A heavy Low band usually means a policy is doing the work - blanket invite or external-link blocking, not a wave of phishing.
Top blocked domains
top 8- 1discord.gg412
- 2bit.ly168
- 3tenor.com121
- 4free-nitr0-gift.ru96
- 5steamcommunlty.com74
- 6t.me55
- 7grabify.link38
- 8shorturl.at24
Top offenders
top 8- 1raid_acct_041763
- 2giveaway.bot51
- 3nitro_drops44
- 4kai#009229
- 5mira21
- 6410299184xxxxxxxxx17
- 7sol_77712
- 8devon9
Shows the stored tag when there is one, otherwise the raw user ID.
Blocked by protection layer
Which module actually caught it, attributed from the action the bot logged.
- Link protection968
- Automod249
- Honeypot96
- Member Defense71
- Webhook Guard39
- QR / Attachment Guard24
- Anti-Nuke22
- AI moderation15
Activity by hour (UTC)
When your server gets hit. Buckets follow the database calendar, which is UTC on the standard host.
Busiest hour
17:00 UTC
Busiest day of week
Saturday
Member Defense
same 30 day window3
Raids
128
Suspicious joins
41
Account blocks
96
Honeypot
Honest by construction. AntiLink records only flagged join events - raid detections, joins caught inside a raid window, account-age blocks and honeypot triggers. It does not log every join and leave, so this is defense activity, not membership growth or churn. We would rather show you less than imply a number we never measured.
Green up and red down would be a lie here.
On a security counter, direction is not judgement. Blocks rising can mean an attack was caught early. Blocks falling can mean protection was switched off, or a channel was quietly exempted. Painting one green and the other red would tell you a story the data cannot support.
So the trend badge is deliberately grey. It gives you the direction and the percentage, then gets out of the way and lets you read the layer split, the risk mix and your own settings.
The comparison also uses two equal windows of complete days, so a flat server never reads "down 14%" at breakfast and "down 1%" at midnight.
Same badge, opposite stories
1,484
▲ 23%Could be a raid wave that Member Defense absorbed. Could be a new invite policy catching traffic that was always there.
311
▼ 79%Could be a quiet month. Could be that someone switched the scanner off last Tuesday. Only the layer split and your settings can say which.
402
no changeA flat period says so plainly instead of inventing a fraction of a percent.
It invents nothing
Analytics is a read-only lens. It adds no tracking, stores no message content and builds no member profiles. Every figure on the deck is an aggregate query over two tables the bot was already writing while it protected your server.
The moderation log
the same feed behind Protection Logs
Already holds every blocked action with its risk level, domain, user, channel and reason. The gauges, the day chart, the risk mix, the layer split, the hour rhythm, the top domains and the top offenders all read from it.
The Member Defense audit trail
raids, screening and honeypot
Already holds the flagged join events: raid detections, joins caught inside a raid window, account-age blocks and honeypot triggers. The Member Defense strip and its daily chart come from here.
Read-only, always
Analytics cannot change a setting, take an action, or delete anything. It reads and summarizes, nothing else.
Fail-soft panels
If one query errors, that panel shows an empty state. The rest of the deck still renders.
Bounded output
Top domains and top offenders cap at 8 rows each, and the CSV export caps at 5,000 rows.
Take the readout with you
Whatever window is on screen is the window that leaves the page - as a spreadsheet, as a PDF, or as a recap the bot posts for you.
CSV export
BasicThe raw security events for the selected window, newest first, ready for a spreadsheet.
Columns
Commas, quotes and newlines are escaped, so it opens cleanly. The download re-checks that you can manage the server and returns a plain 403 if you cannot.
Printable report
BasicA clean light-themed document view of the same numbers. Save it as a PDF straight from your browser, with no plugin and no extra service.
Security analytics report
Last 30 days
Scheduled recap
AntiLink PlusStop remembering to look. AntiLink posts the recap into a channel you choose, every week or every month.
- Threats blocked, with the trend
- Risk-level breakdown
- Top blocked domains
- Protection score
- Suggested next steps
The blocked total and its trend always appear. Every other section is a checkbox you control.
Stop guessing. Read the deck.
Add AntiLink, let it protect for a week, then open Analytics. There is nothing to switch on - the deck fills itself in from the work the bot is already doing.