1C:Enterprise Event Log
1C:Enterprise 8.3.27 event-log collector projection for a client/server, single-data-area infobase: ECS-style JSON with snake_case source fields under one_c.event_log, not a native XML or .lgf export and without event.original. Six staff accounts, four reusable temporary account names and five configured objects with explicit permissions. Recurring episodes, weekly by default, join an administrator's failed logins, a temporary FullAccess account, its payroll reads, its deletion and an event-log reduction.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/application-1c/generator.yml \
--id one-c \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| _$Access$_.Access | Successful controlled read with one nested logged row | 91.93% background share | database |
| _$Access$_.AccessDenied | Object-level Read permission denial | 4.01% background share | database |
| _$Session$_.Authentication | Successful authentication opens a session | 2.84% background share | authentication |
| _$User$_.Update | Administrator updates another staff account; unproven native Data omitted | 0.54% background share | iam |
| _$User$_.New | Administrator creates one temporary account | 0.19% background share | iam |
| _$User$_.Delete | Administrator deletes that temporary incarnation | 0.19% background share | iam |
| _$InfoBase$_.EventLogReduce | Administrator reduces records older than the assumed cutoff | 0.15% background share | configuration |
| _$Session$_.AuthenticationError | Failed attempt; no native authenticated UUID is asserted | 0.15% background share | authentication |
Realism Features
- Six staff accounts (two accountants, one sales and one warehouse user, two administrators), four temporary account names reused after deletion and five fictional configuration objects. Accountants read all five objects; Sales and Warehouse are denied the payroll register. These are configured scenario permissions, not privileges inferred from role names.
- About 8,500 records a day: staff activity at about 350 records per hour, the hourly count varying by up to 10%, and administrator logins about 120 times a day, the day count varying by up to 30%, plus a fresh session for half of their management tasks. Rates do not vary by time of day or day of week. Source time has whole seconds, and about 5% of records share their second with the previous one.
- The data opens mid-stream: most staff already hold a session that began earlier. Sessions last a random lognormal lifetime (median about 70 minutes), and the operation after a login follows seconds later (median 29 s). Session and connection numbers grow in random steps. Session end is not recorded, because its native record body was not established.
- About 5% of login attempts fail (4-5% for staff, about 6% for administrators); a failed attempt is retried after a median 22 s, and 68% of runs end in a successful login. Run counts fall with the number of failures: administrator runs of four or more failures occur about 0.9 times a day, some of them from a maintenance client retrying a stale saved password.
- About 16 temporary-account lifecycles a day, each administrator keeping two of the four names and using the others only while both of its own are taken. The account logs in from its creator's workstation, reads the payroll register 1-113 times (median 6), and the creator deletes it in 90% of lifecycles, lifespans median about 13 minutes. About 13 event-log reductions a day; 72% of deletions are followed within 30 minutes by the deleter's reduction, but only 10% of same-administrator deletions that end four failures, a login and the creation within 30 minutes of the first failure (always after those 30 minutes), against 77% of other deletions.
- With anomaly_mode true each episode adds its own records, so counts of the chain parts are about one per episode higher than in background; the weekly default keeps the episode rare against about six administrator runs of four or more failed logins a week. In about one episode in seven an ordinary login by the same administrator falls between its failed attempts.
- The 23-field union of the documented XML elements is field presence, not native value fidelity. Failed authentications omit native user attribution; update, deletion and reduction omit unproven Data, and management targets are synthetic enrichment. Reductions cut assumed history before the current day, so no recent-log erasure or exfiltration is claimed; full native exports and live parser parity are unverified.
Sample Output
{
"@timestamp": "2026-09-01T21:04:45+00:00",
"ecs": {
"version": "8.11.0"
},
"event": {
"kind": "event",
"module": "one_c",
"dataset": "one_c.event_log",
"action": "_$User$_.New",
"category": [
"iam"
],
"type": [
"creation"
],
"outcome": "success"
},
"host": {
"name": "srvr-1c-01.example.test"
},
"service": {
"name": "AccountingDemo"
},
"user": {
"name": "admin01",
"id": "00000000-0000-0000-0000-000000000105",
"target": {
"name": "svc_audit_01",
"id": "03c84f98-238d-48b6-89c8-ce448c4370b8"
}
},
"client": {
"address": "ADM-WS-01"
},
"related": {
"user": [
"admin01",
"svc_audit_01"
],
"hosts": [
"ADM-WS-01"
]
},
"message": "Пользователи.Новый пользователь",
"one_c": {
"event_log": {
"level": "Information",
"date": "2026-09-01T21:04:45+00:00",
"application": "Enterprise",
"application_presentation": "1C:Enterprise",
"event_name": "_$User$_.New",
"event_presentation": "Пользователи.Новый пользователь",
"user_id": "00000000-0000-0000-0000-000000000105",
"user_name": "admin01",
"computer": "ADM-WS-01",
"metadata_name": "",
"metadata_presentation": "",
"comment": "",
"data": {
"Roles": [
"Roles.FullAccess"
]
},
"data_presentation": "",
"transaction_status": "NotApplicable",
"transaction_id": "",
"connection": 634,
"session": 1620,
"server_name": "srvr-1c-01.example.test",
"port": 1541,
"sync_port": 1542,
"session_data_separation": {},
"session_data_separation_presentation": []
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| infobase | AccountingDemo | Synthetic configuration/infobase name |
| server_name | srvr-1c-01.example.test | Working server context |
| host_name | srvr-1c-01.example.test | Synthetic collector host |
| server_port | 1541 | Main server port |
| sync_port | 1542 | Auxiliary server port |
| ecs_version | 8.11.0 | Normalized ECS context |
| anomaly_mode | true | Add recurring anomaly episodes; false produces only background |
| anomaly_interval_hours | 168 | Source-time interval between episodes, clamped to at least one hour |
Related Generators
1C:Enterprise Technological Log
1C:Enterprise 8.3.27 technological-log JSON records (SCALL, CALL, TLOCK, EXCP) of one rphost process serving fourteen client and service sessions of one infobase, in an ECS envelope. About 44,000 records a day: interactive users follow a working day in UTC, background jobs keep the same pace day and night. Managed locks on document keys are granted at once, queued, or time out after 20 seconds. Recurring episodes are lock convoys: one very long posting blocks a busy document key until six distinct sessions have timed out on it within 50 minutes.
Nextcloud Admin Audit
Nextcloud 35.0.0 admin_audit HTTP records from the dedicated audit.log file backend, with each native JSON line in event.original and parsed under nextcloud.audit, for testing detections on logins, file access and public links. 180 users work in sessions over 1,154 files, about 10,800 records a day. Recurring episodes show a guessed password followed by publishing a file for outside access through a public link.
Atlassian Jira security logs
About 6,600 records/day from one Jira node and 512 accounts, with native security messages and ECS enrichment.