Yandex Cloud Audit Trails
Yandex Cloud Audit Trails management events for one organization, cloud and folder, as ECS records with the native audit record in event.original and parsed under yandex_cloud.audit, for SIEM content that watches cloud IAM and Compute changes. Successful control-plane operations of six federated operators and a CI runner autoscaler. Recurring episodes show an operator provisioning a service account with persistent write access.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/cloud-yandex-audit-trails/generator.yml \
--id yandex-audit \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| compute.UpdateInstance | Label update on a permanent, CI or runner VM | 52.5% measured share | configuration |
| compute.CreateInstance | Temporary CI VM or CI runner VM | 15.4% measured share | configuration |
| compute.DeleteInstance | Cleanup of a CI or runner VM | 15.4% measured share | configuration |
| resourcemanager.UpdateFolderAccessBindings | ADD or REMOVE of one folder role for a service account | 6.3% measured share | iam |
| iam.CreateAccessKey | Static access key for a service account | 3.5% measured share | iam |
| iam.DeleteAccessKey | Key rotation or cleanup | 3.1% measured share | iam |
| iam.CreateServiceAccount | New service account | 2.2% measured share | iam |
| iam.DeleteServiceAccount | Cleanup of a created account after its keys and roles | 1.6% measured share | iam |
Realism Features
- Six federated operators (about a third of records) with different activity levels work in sessions on an office-hours curve (UTC+3), from an office or a VPN address; operations in a session are one to a few minutes apart, never seconds.
- Operators update labels on 64 permanent VMs and live CI VMs, create temporary CI VMs deleted after hours by the creator or another operator (at most eight at a time), provision service accounts with usually a folder role (editor, viewer, storage.editor or compute.editor) and often a static key within minutes, and maintain roles and keys on 24 permanent and created accounts.
- A CI runner autoscaler service account (about two thirds of records) creates runner VMs for queued jobs, labels a runner busy with the job ID for every job and idle after its last job and after some others, and deletes it once idle: about 54 calls per hour in 06:00-18:00 UTC and 20 at night, never IAM. About 1,300 records per day on working days and weekends alike, with ±10% day-to-day variation.
- Created accounts are cleaned up after about a day: keys deleted, roles removed, then the account deleted, a few minutes apart. ADD never repeats a held binding, REMOVE only follows an ADD, a key is deleted only once, an account holds at most two background keys, and at most 70 created accounts are live at a time.
- event.original keeps the field order of the vendor example on one line, and details follow the event references in snake_case. user.target is an ECS mapping of the service account an event acts on. No live tenant log was compared, so field-complete parity is not claimed.
- Optional token_info, request_parameters, response, error and remote_port are omitted, as are status and expires_at in DeleteServiceAccount; failed and cancelled operations and transport containers are not modeled. User agents (one yc CLI version per operator, a gRPC Go client for the autoscaler) and product, subnet and federation IDs are synthetic, and the VM pools assume Compute quotas above the default of 12 VMs.
- Rates, lifetimes and weights are synthetic, not measured production values. With anomaly_mode true, counts of the chain parts are about one per episode higher than without episodes.
Sample Output
{
"@timestamp": "2026-09-28T12:46:42.251134Z",
"ecs": {
"version": "8.17.0"
},
"event": {
"kind": "event",
"module": "yandex_cloud",
"dataset": "yandex_cloud.audit",
"id": "e22f1c47-2596-4cba-8d4d-514812201ddf",
"action": "CreateAccessKey",
"category": [
"iam"
],
"type": [
"creation"
],
"outcome": "success",
"original": "{\"event_id\": \"e22f1c47-2596-4cba-8d4d-514812201ddf\", \"event_source\": \"iam\", \"event_type\": \"yandex.cloud.audit.iam.CreateAccessKey\", \"event_time\": \"2026-09-28T12:46:42.251134Z\", \"authentication\": {\"authenticated\": true, \"subject_type\": \"FEDERATED_USER_ACCOUNT\", \"subject_id\": \"aje4a90f6b1d3c28e57d\", \"subject_name\": \"sre.oncall\", \"federation_id\": \"bpffd0b1506f5e3af1f1\", \"federation_name\": \"contoso\", \"federation_type\": \"PRIVATE_FEDERATION\"}, \"authorization\": {\"authorized\": true}, \"resource_metadata\": {\"path\": [{\"resource_type\": \"organization-manager.organization\", \"resource_id\": \"bpf8fce59da310dc940c\", \"resource_name\": \"contoso-org\"}, {\"resource_type\": \"resource-manager.cloud\", \"resource_id\": \"b1g0a10235b15143e07a\", \"resource_name\": \"contoso-cloud\"}, {\"resource_type\": \"resource-manager.folder\", \"resource_id\": \"b1g2a15c9bea04fe16e5\", \"resource_name\": \"production\"}]}, \"request_metadata\": {\"remote_address\": \"10.60.1.85\", \"user_agent\": \"yc/0.155\", \"request_id\": \"5ed5ca15-21fa-4baf-b540-59e4ad785929\"}, \"event_status\": \"DONE\", \"details\": {\"access_key_id\": \"ajecf34ee1c532cf2805\", \"service_account_id\": \"aje7dae6f30b3b2df237\", \"service_account_name\": \"svc-maint-7dae6f30b3b2df237\", \"key_id\": \"YCMnoToREoyxIiOvrAxpojejX\", \"description\": \"Maintenance automation\", \"created_at\": \"2026-09-28T12:46:42.251134Z\"}}"
},
"source": {
"ip": "10.60.1.85"
},
"user": {
"id": "aje4a90f6b1d3c28e57d",
"name": "sre.oncall",
"target": {
"id": "aje7dae6f30b3b2df237",
"name": "svc-maint-7dae6f30b3b2df237"
}
},
"related": {
"ip": [
"10.60.1.85"
],
"user": [
"sre.oncall",
"svc-maint-7dae6f30b3b2df237"
]
},
"cloud": {
"provider": "yandex",
"account": {
"id": "b1g0a10235b15143e07a"
}
},
"yandex_cloud": {
"audit": {
"event_id": "e22f1c47-2596-4cba-8d4d-514812201ddf",
"event_source": "iam",
"event_type": "yandex.cloud.audit.iam.CreateAccessKey",
"event_time": "2026-09-28T12:46:42.251134Z",
"authentication": {
"authenticated": true,
"subject_type": "FEDERATED_USER_ACCOUNT",
"subject_id": "aje4a90f6b1d3c28e57d",
"subject_name": "sre.oncall",
"federation_id": "bpffd0b1506f5e3af1f1",
"federation_name": "contoso",
"federation_type": "PRIVATE_FEDERATION"
},
"authorization": {
"authorized": true
},
"resource_metadata": {
"path": [
{
"resource_type": "organization-manager.organization",
"resource_id": "bpf8fce59da310dc940c",
"resource_name": "contoso-org"
},
{
"resource_type": "resource-manager.cloud",
"resource_id": "b1g0a10235b15143e07a",
"resource_name": "contoso-cloud"
},
{
"resource_type": "resource-manager.folder",
"resource_id": "b1g2a15c9bea04fe16e5",
"resource_name": "production"
}
]
},
"request_metadata": {
"remote_address": "10.60.1.85",
"user_agent": "yc/0.155",
"request_id": "5ed5ca15-21fa-4baf-b540-59e4ad785929"
},
"event_status": "DONE",
"details": {
"access_key_id": "ajecf34ee1c532cf2805",
"service_account_id": "aje7dae6f30b3b2df237",
"service_account_name": "svc-maint-7dae6f30b3b2df237",
"key_id": "YCMnoToREoyxIiOvrAxpojejX",
"description": "Maintenance automation",
"created_at": "2026-09-28T12:46:42.251134Z"
}
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| cloud_id | b1g0a10235b15143e07a | Cloud in the resource path and cloud.account.id |
| folder_id | b1g2a15c9bea04fe16e5 | Folder in the resource path and in binding changes |
| organization_id | bpf8fce59da310dc940c | Organization in the resource path |
| service_account_prefix | svc-maint | Name prefix of created service accounts; a random suffix keeps names unique |
| anomaly_interval_hours | 24 | Hours between episode starts, at least 2 |
| anomaly_mode | true | true adds recurring anomaly episodes; false emits background only |
Related Generators
AWS CloudTrail Management Events
AWS CloudTrail audit trail — API calls across EC2, IAM, STS, and S3 from a multi-account organization. Includes console logins, role assumptions, error injection, and 4 identity types.
AWS GuardDuty Findings
AWS GuardDuty threat detection findings across EC2, IAM, and S3 resources. Covers 8 categories — Recon, UnauthorizedAccess, Policy, Trojan, Impact, CryptoCurrency, Stealth, and Backdoor — with 27 finding types, 10 threat actor IPs, and geo/ASN enrichment.
AWS VPC Flow Logs
AWS VPC Flow Logs (v5) — network traffic records across multiple accounts, VPCs, and subnets. TCP/UDP/ICMP flows with ACCEPT/REJECT actions, NAT gateway traffic, and realistic byte/packet distributions.