Nextcloud Admin Audit
Nextcloud 35.0.0 admin_audit HTTP records from the dedicated audit.log file backend, with each native JSON line in event.original and parsed under nextcloud.audit, for testing detections on logins, file access and public links. 180 users work in sessions over 1,154 files, about 10,800 records a day. Recurring episodes show a guessed password followed by publishing a file for outside access through a public link.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/application-nextcloud-audit/generator.yml \
--id nextcloud-audit \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| File accessed | DAV file read | 57.5% measured share (57.5-57.9% by week) | file |
| File written to | DAV file update | 24.0% measured share (23.7-24.0% by week) | file |
| Login attempt | Password login request | 8.4% measured share (8.4-8.5% by week) | authentication |
| Login successful | Login result: password accepted | 7.7% measured share (7.7-7.8% by week) | authentication |
| Shared via link | Public link creation | 0.9% measured share (0.7-1.1% by week) | file |
| Login failed | Login result: password rejected | 0.7% measured share (0.7% by week) | authentication |
| Expiration removed | Public link expiration removal | 0.5% measured share (0.4-0.6% by week) | file |
| Permissions changed | Public link changed from read-only (1) to read and update (3) | 0.2% measured share (0.2-0.3% by week) | file |
Realism Features
- About 10,800 records a day on a UTC working-day curve: 0.27 records/s at 10-15, 0.20 at 08-10 and 15-17, 0.12 at 07-08 and 17-19, and 0.04 at night (19-07); the daily total varies by about ±10% from day to day. Timestamps have one-second resolution, as in the native log; records of one moment, such as a mistyped password and its retry, are a few seconds apart in office hours and 15-25 seconds apart at night, rather than milliseconds.
- 180 users with 1,154 files work in sessions from the office address or their own home address, busier users more often. Half of the sessions start with a password login in the web interface; 3% of those logins follow one to five mistyped passwords seconds apart, and a tenth of those are given up. Sessions read and write the user's files minutes apart, often the file just used, and now and then create a read-only public link with a default expiration date, remove a link's expiration or allow updates through it; each property of a link changes at most once.
- A few web sessions are opened to share a file with someone outside: the user reads the file, creates a public link, in half of the cases removes its expiration minutes later and sometimes then allows updates. Their share of web sessions drifts between 4% and 12% from day to day, so users create about 75-120 public links a day; about half later lose their expiration date and about a quarter are opened for updates.
- About once a day a sync client with an outdated password retries three to eight times about a minute apart, and half of them end with a successful login; about five times a day an address from the documentation ranges tries passwords for a user without success. About 8% of login attempts fail.
- A login attempt and its result share one reqId and native timestamp; separate requests have distinct IDs, so reqId does not prove a persistent session. Public link IDs grow by one to four per link. The permission-change message gives the path relative to the owner's files folder, while reads, writes and link creation give the full path; file.path holds the full path in every file and link record.
- Every step of the chain occurs in ordinary traffic. A typical week of background holds about 75-90 cases of three failed logins of one user and address within 10 minutes, 55-65 cases of three failures followed by a success within an hour, and 80-120 reads followed within an hour by a link, expiration removal and permission change for the same file; about one to five a week reach the expiration removal after three failures, and at most two also reach the permission change after two failures. With anomaly_mode true, counts of these chain parts are about one per episode higher (about seven more a week at the default interval, 21 at 8 hours), several times the background count for the longest parts.
- Field coverage is 13/13 non-optional native fields of the tagged 35.0.0 serializer, in its field order with compact separators. No captured production audit.log line from a running 35.0.0 server was available, so request routes and end-to-end native bytes remain unconfirmed; the native version 35.0.0.10 is the internal four-part number, and the ECS agent.type and log.file.path fields model a file collector.
- The modeled sharing policy sets a default public-link expiration without enforcing it and permits editing a public file link. Rates, session shapes, the sharing share and addresses are synthetic workload settings on UTC working hours, and compatibility with the KUMA Nextcloud source (26.0.4 via syslog) is not asserted.
Sample Output
{
"@timestamp": "2026-09-21T11:08:04+00:00",
"agent": {
"name": "cloud-01.corp.example",
"type": "filebeat"
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "share-create",
"category": [
"file"
],
"dataset": "nextcloud.audit",
"kind": "event",
"original": "{\"reqId\":\"wQvQ0YOnvKhJDWzisYVe\",\"level\":1,\"time\":\"2026-09-21T11:08:04+00:00\",\"remoteAddr\":\"203.0.113.29\",\"user\":\"ulyana\",\"app\":\"admin_audit\",\"method\":\"POST\",\"url\":\"/ocs/v2.php/apps/files_sharing/api/v1/shares\",\"scriptName\":\"/ocs/v2.php\",\"message\":\"The file \\\"/ulyana/files/HR/Onboarding-02.xlsx\\\" with ID \\\"14432\\\" has been shared via link with permissions \\\"1\\\" (Share ID: 32120)\",\"userAgent\":\"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/126.0.0.0 Safari/537.36\",\"version\":\"35.0.0.10\",\"data\":{\"app\":\"admin_audit\"}}",
"outcome": "success",
"type": [
"creation"
]
},
"file": {
"path": "/ulyana/files/HR/Onboarding-02.xlsx"
},
"host": {
"name": "cloud-01.corp.example"
},
"http": {
"request": {
"method": "POST"
}
},
"log": {
"file": {
"path": "/var/www/html/data/audit.log"
},
"level": "info"
},
"message": "The file \"/ulyana/files/HR/Onboarding-02.xlsx\" with ID \"14432\" has been shared via link with permissions \"1\" (Share ID: 32120)",
"nextcloud": {
"audit": {
"app": "admin_audit",
"data": {
"app": "admin_audit"
},
"level": 1,
"message": "The file \"/ulyana/files/HR/Onboarding-02.xlsx\" with ID \"14432\" has been shared via link with permissions \"1\" (Share ID: 32120)",
"method": "POST",
"remoteAddr": "203.0.113.29",
"reqId": "wQvQ0YOnvKhJDWzisYVe",
"scriptName": "/ocs/v2.php",
"time": "2026-09-21T11:08:04+00:00",
"url": "/ocs/v2.php/apps/files_sharing/api/v1/shares",
"user": "ulyana",
"userAgent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/126.0.0.0 Safari/537.36",
"version": "35.0.0.10"
}
},
"related": {
"ip": [
"203.0.113.29"
],
"user": [
"ulyana"
]
},
"source": {
"ip": "203.0.113.29"
},
"tags": [
"nextcloud",
"admin_audit"
],
"url": {
"path": "/ocs/v2.php/apps/files_sharing/api/v1/shares"
},
"user": {
"name": "ulyana"
},
"user_agent": {
"original": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/126.0.0.0 Safari/537.36"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| server_name | cloud-01.corp.example | ECS server host name; also fixes the user organisation |
| server_version | 35.0.0.10 | Four-part native log version for Nextcloud 35.0.0 |
| audit_log_path | /var/www/html/data/audit.log | ECS path of the collected audit file; does not change local generator output |
| first_share_id | 32019 | Public-link IDs start after this value |
| anomaly_interval_hours | 24 | Hours from one episode start to the next due time, 3 to 8,760 |
| anomaly_mode | true | Add the recurring anomaly episodes to the background; false emits only background |
Related Generators
1C:Enterprise Event Log
1C:Enterprise 8.3.27 event-log collector projection for a client/server, single-data-area infobase: ECS-style JSON with snake_case source fields under one_c.event_log, not a native XML or .lgf export and without event.original. Six staff accounts, four reusable temporary account names and five configured objects with explicit permissions. Recurring episodes, weekly by default, join an administrator's failed logins, a temporary FullAccess account, its payroll reads, its deletion and an event-log reduction.
1C:Enterprise Technological Log
1C:Enterprise 8.3.27 technological-log JSON records (SCALL, CALL, TLOCK, EXCP) of one rphost process serving fourteen client and service sessions of one infobase, in an ECS envelope. About 44,000 records a day: interactive users follow a working day in UTC, background jobs keep the same pace day and night. Managed locks on document keys are granted at once, queued, or time out after 20 seconds. Recurring episodes are lock convoys: one very long posting blocks a busy document key until six distinct sessions have timed out on it within 50 minutes.
Atlassian Jira security logs
About 6,600 records/day from one Jira node and 512 accounts, with native security messages and ECS enrichment.