How to Read Shutdown Event Logs in Windows   Information You can use Event Viewer to view the date, time, and user details of all shutdown
Check out key metrics that you need to monitor & why they’re essential to maintaining the health and performance of your Elasticsearch cluster.
Specifically, it tells how to ship Apache and Nginx logs over rsyslog.
A key best practice for logging is to centralize or aggregate your logs in a single location, especially if you have multiple servers or architecture tiers. Modern applications often have several tiers of infrastructure that can include a mix of on-premises servers…
[The Elastic ELK stack is popular but probably overkill; Graylog is related]
Similar guide:
https://sematext.com/blog/log-aggregation/
Describes the best practices, location, values, and security considerations for the Interactive logon Do not display last user name security policy setting.
IPBan: https://www.digitalruby.com/ipban/ [Windows/Linux only]
SSHguard: http://www.sshguard.net
Sentry? https://github.com/msimerson/sentry/ [Perl, not sure how automated it is]
I found it in group policy for workstations, too:
Administrative Templates, Windows Components, Remote Desktop Services, Remote Desktop Session Host, Session Time Limits
conceivably would work without GPS
how to set the time until screen saver activation...?