Hub
Application

Nextcloud Admin Audit

Nextcloud 35.0.0 admin_audit HTTP records from the dedicated audit.log file backend, with each native JSON line in event.original and parsed under nextcloud.audit, for testing detections on logins, file access and public links. 180 users work in sessions over 1,154 files, about 10,800 records a day. Recurring episodes show a guessed password followed by publishing a file for outside access through a public link.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/application-nextcloud-audit/generator.yml \
  --id nextcloud-audit \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
File accessedDAV file read57.5% measured share (57.5-57.9% by week)file
File written toDAV file update24.0% measured share (23.7-24.0% by week)file
Login attemptPassword login request8.4% measured share (8.4-8.5% by week)authentication
Login successfulLogin result: password accepted7.7% measured share (7.7-7.8% by week)authentication
Shared via linkPublic link creation0.9% measured share (0.7-1.1% by week)file
Login failedLogin result: password rejected0.7% measured share (0.7% by week)authentication
Expiration removedPublic link expiration removal0.5% measured share (0.4-0.6% by week)file
Permissions changedPublic link changed from read-only (1) to read and update (3)0.2% measured share (0.2-0.3% by week)file

Realism Features

  • About 10,800 records a day on a UTC working-day curve: 0.27 records/s at 10-15, 0.20 at 08-10 and 15-17, 0.12 at 07-08 and 17-19, and 0.04 at night (19-07); the daily total varies by about ±10% from day to day. Timestamps have one-second resolution, as in the native log; records of one moment, such as a mistyped password and its retry, are a few seconds apart in office hours and 15-25 seconds apart at night, rather than milliseconds.
  • 180 users with 1,154 files work in sessions from the office address or their own home address, busier users more often. Half of the sessions start with a password login in the web interface; 3% of those logins follow one to five mistyped passwords seconds apart, and a tenth of those are given up. Sessions read and write the user's files minutes apart, often the file just used, and now and then create a read-only public link with a default expiration date, remove a link's expiration or allow updates through it; each property of a link changes at most once.
  • A few web sessions are opened to share a file with someone outside: the user reads the file, creates a public link, in half of the cases removes its expiration minutes later and sometimes then allows updates. Their share of web sessions drifts between 4% and 12% from day to day, so users create about 75-120 public links a day; about half later lose their expiration date and about a quarter are opened for updates.
  • About once a day a sync client with an outdated password retries three to eight times about a minute apart, and half of them end with a successful login; about five times a day an address from the documentation ranges tries passwords for a user without success. About 8% of login attempts fail.
  • A login attempt and its result share one reqId and native timestamp; separate requests have distinct IDs, so reqId does not prove a persistent session. Public link IDs grow by one to four per link. The permission-change message gives the path relative to the owner's files folder, while reads, writes and link creation give the full path; file.path holds the full path in every file and link record.
  • Every step of the chain occurs in ordinary traffic. A typical week of background holds about 75-90 cases of three failed logins of one user and address within 10 minutes, 55-65 cases of three failures followed by a success within an hour, and 80-120 reads followed within an hour by a link, expiration removal and permission change for the same file; about one to five a week reach the expiration removal after three failures, and at most two also reach the permission change after two failures. With anomaly_mode true, counts of these chain parts are about one per episode higher (about seven more a week at the default interval, 21 at 8 hours), several times the background count for the longest parts.
  • Field coverage is 13/13 non-optional native fields of the tagged 35.0.0 serializer, in its field order with compact separators. No captured production audit.log line from a running 35.0.0 server was available, so request routes and end-to-end native bytes remain unconfirmed; the native version 35.0.0.10 is the internal four-part number, and the ECS agent.type and log.file.path fields model a file collector.
  • The modeled sharing policy sets a default public-link expiration without enforcing it and permits editing a public file link. Rates, session shapes, the sharing share and addresses are synthetic workload settings on UTC working hours, and compatibility with the KUMA Nextcloud source (26.0.4 via syslog) is not asserted.

Sample Output

{
  "@timestamp": "2026-09-21T11:08:04+00:00",
  "agent": {
    "name": "cloud-01.corp.example",
    "type": "filebeat"
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "share-create",
    "category": [
      "file"
    ],
    "dataset": "nextcloud.audit",
    "kind": "event",
    "original": "{\"reqId\":\"wQvQ0YOnvKhJDWzisYVe\",\"level\":1,\"time\":\"2026-09-21T11:08:04+00:00\",\"remoteAddr\":\"203.0.113.29\",\"user\":\"ulyana\",\"app\":\"admin_audit\",\"method\":\"POST\",\"url\":\"/ocs/v2.php/apps/files_sharing/api/v1/shares\",\"scriptName\":\"/ocs/v2.php\",\"message\":\"The file \\\"/ulyana/files/HR/Onboarding-02.xlsx\\\" with ID \\\"14432\\\" has been shared via link with permissions \\\"1\\\" (Share ID: 32120)\",\"userAgent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/126.0.0.0 Safari/537.36\",\"version\":\"35.0.0.10\",\"data\":{\"app\":\"admin_audit\"}}",
    "outcome": "success",
    "type": [
      "creation"
    ]
  },
  "file": {
    "path": "/ulyana/files/HR/Onboarding-02.xlsx"
  },
  "host": {
    "name": "cloud-01.corp.example"
  },
  "http": {
    "request": {
      "method": "POST"
    }
  },
  "log": {
    "file": {
      "path": "/var/www/html/data/audit.log"
    },
    "level": "info"
  },
  "message": "The file \"/ulyana/files/HR/Onboarding-02.xlsx\" with ID \"14432\" has been shared via link with permissions \"1\" (Share ID: 32120)",
  "nextcloud": {
    "audit": {
      "app": "admin_audit",
      "data": {
        "app": "admin_audit"
      },
      "level": 1,
      "message": "The file \"/ulyana/files/HR/Onboarding-02.xlsx\" with ID \"14432\" has been shared via link with permissions \"1\" (Share ID: 32120)",
      "method": "POST",
      "remoteAddr": "203.0.113.29",
      "reqId": "wQvQ0YOnvKhJDWzisYVe",
      "scriptName": "/ocs/v2.php",
      "time": "2026-09-21T11:08:04+00:00",
      "url": "/ocs/v2.php/apps/files_sharing/api/v1/shares",
      "user": "ulyana",
      "userAgent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/126.0.0.0 Safari/537.36",
      "version": "35.0.0.10"
    }
  },
  "related": {
    "ip": [
      "203.0.113.29"
    ],
    "user": [
      "ulyana"
    ]
  },
  "source": {
    "ip": "203.0.113.29"
  },
  "tags": [
    "nextcloud",
    "admin_audit"
  ],
  "url": {
    "path": "/ocs/v2.php/apps/files_sharing/api/v1/shares"
  },
  "user": {
    "name": "ulyana"
  },
  "user_agent": {
    "original": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/126.0.0.0 Safari/537.36"
  }
}

Parameters

ParameterDefaultDescription
server_namecloud-01.corp.exampleECS server host name; also fixes the user organisation
server_version35.0.0.10Four-part native log version for Nextcloud 35.0.0
audit_log_path/var/www/html/data/audit.logECS path of the collected audit file; does not change local generator output
first_share_id32019Public-link IDs start after this value
anomaly_interval_hours24Hours from one episode start to the next due time, 3 to 8,760
anomaly_modetrueAdd the recurring anomaly episodes to the background; false emits only background

Related Generators