Hub
Application

1C:Enterprise Event Log

1C:Enterprise 8.3.27 event-log collector projection for a client/server, single-data-area infobase: ECS-style JSON with snake_case source fields under one_c.event_log, not a native XML or .lgf export and without event.original. Six staff accounts, four reusable temporary account names and five configured objects with explicit permissions. Recurring episodes, weekly by default, join an administrator's failed logins, a temporary FullAccess account, its payroll reads, its deletion and an event-log reduction.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/application-1c/generator.yml \
  --id one-c \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
_$Access$_.AccessSuccessful controlled read with one nested logged row91.93% background sharedatabase
_$Access$_.AccessDeniedObject-level Read permission denial4.01% background sharedatabase
_$Session$_.AuthenticationSuccessful authentication opens a session2.84% background shareauthentication
_$User$_.UpdateAdministrator updates another staff account; unproven native Data omitted0.54% background shareiam
_$User$_.NewAdministrator creates one temporary account0.19% background shareiam
_$User$_.DeleteAdministrator deletes that temporary incarnation0.19% background shareiam
_$InfoBase$_.EventLogReduceAdministrator reduces records older than the assumed cutoff0.15% background shareconfiguration
_$Session$_.AuthenticationErrorFailed attempt; no native authenticated UUID is asserted0.15% background shareauthentication

Realism Features

  • Six staff accounts (two accountants, one sales and one warehouse user, two administrators), four temporary account names reused after deletion and five fictional configuration objects. Accountants read all five objects; Sales and Warehouse are denied the payroll register. These are configured scenario permissions, not privileges inferred from role names.
  • About 8,500 records a day: staff activity at about 350 records per hour, the hourly count varying by up to 10%, and administrator logins about 120 times a day, the day count varying by up to 30%, plus a fresh session for half of their management tasks. Rates do not vary by time of day or day of week. Source time has whole seconds, and about 5% of records share their second with the previous one.
  • The data opens mid-stream: most staff already hold a session that began earlier. Sessions last a random lognormal lifetime (median about 70 minutes), and the operation after a login follows seconds later (median 29 s). Session and connection numbers grow in random steps. Session end is not recorded, because its native record body was not established.
  • About 5% of login attempts fail (4-5% for staff, about 6% for administrators); a failed attempt is retried after a median 22 s, and 68% of runs end in a successful login. Run counts fall with the number of failures: administrator runs of four or more failures occur about 0.9 times a day, some of them from a maintenance client retrying a stale saved password.
  • About 16 temporary-account lifecycles a day, each administrator keeping two of the four names and using the others only while both of its own are taken. The account logs in from its creator's workstation, reads the payroll register 1-113 times (median 6), and the creator deletes it in 90% of lifecycles, lifespans median about 13 minutes. About 13 event-log reductions a day; 72% of deletions are followed within 30 minutes by the deleter's reduction, but only 10% of same-administrator deletions that end four failures, a login and the creation within 30 minutes of the first failure (always after those 30 minutes), against 77% of other deletions.
  • With anomaly_mode true each episode adds its own records, so counts of the chain parts are about one per episode higher than in background; the weekly default keeps the episode rare against about six administrator runs of four or more failed logins a week. In about one episode in seven an ordinary login by the same administrator falls between its failed attempts.
  • The 23-field union of the documented XML elements is field presence, not native value fidelity. Failed authentications omit native user attribution; update, deletion and reduction omit unproven Data, and management targets are synthetic enrichment. Reductions cut assumed history before the current day, so no recent-log erasure or exfiltration is claimed; full native exports and live parser parity are unverified.

Sample Output

{
  "@timestamp": "2026-09-01T21:04:45+00:00",
  "ecs": {
    "version": "8.11.0"
  },
  "event": {
    "kind": "event",
    "module": "one_c",
    "dataset": "one_c.event_log",
    "action": "_$User$_.New",
    "category": [
      "iam"
    ],
    "type": [
      "creation"
    ],
    "outcome": "success"
  },
  "host": {
    "name": "srvr-1c-01.example.test"
  },
  "service": {
    "name": "AccountingDemo"
  },
  "user": {
    "name": "admin01",
    "id": "00000000-0000-0000-0000-000000000105",
    "target": {
      "name": "svc_audit_01",
      "id": "03c84f98-238d-48b6-89c8-ce448c4370b8"
    }
  },
  "client": {
    "address": "ADM-WS-01"
  },
  "related": {
    "user": [
      "admin01",
      "svc_audit_01"
    ],
    "hosts": [
      "ADM-WS-01"
    ]
  },
  "message": "Пользователи.Новый пользователь",
  "one_c": {
    "event_log": {
      "level": "Information",
      "date": "2026-09-01T21:04:45+00:00",
      "application": "Enterprise",
      "application_presentation": "1C:Enterprise",
      "event_name": "_$User$_.New",
      "event_presentation": "Пользователи.Новый пользователь",
      "user_id": "00000000-0000-0000-0000-000000000105",
      "user_name": "admin01",
      "computer": "ADM-WS-01",
      "metadata_name": "",
      "metadata_presentation": "",
      "comment": "",
      "data": {
        "Roles": [
          "Roles.FullAccess"
        ]
      },
      "data_presentation": "",
      "transaction_status": "NotApplicable",
      "transaction_id": "",
      "connection": 634,
      "session": 1620,
      "server_name": "srvr-1c-01.example.test",
      "port": 1541,
      "sync_port": 1542,
      "session_data_separation": {},
      "session_data_separation_presentation": []
    }
  }
}

Parameters

ParameterDefaultDescription
infobaseAccountingDemoSynthetic configuration/infobase name
server_namesrvr-1c-01.example.testWorking server context
host_namesrvr-1c-01.example.testSynthetic collector host
server_port1541Main server port
sync_port1542Auxiliary server port
ecs_version8.11.0Normalized ECS context
anomaly_modetrueAdd recurring anomaly episodes; false produces only background
anomaly_interval_hours168Source-time interval between episodes, clamped to at least one hour

Related Generators