MongoDB Server Log (mongod JSON)
Structured logv2 JSON server log of one MongoDB Community 7.0 mongod (default verbosity, slowms 100, SCRAM-SHA-256) as shipped by the Elastic mongodb.log integration: the native line byte for byte in event.original and its parsed fields under mongodb.log. About 39,000 lines a day on a UTC hour curve, from service pools, batch jobs and four people that connect, authenticate and run slow reads and exports. Recurring episodes show repeated wrong passwords followed by a single-batch customer export.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/database-mongodb-log/generator.yml \
--id database-mongodb-log \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 51803 | Slow query (COMMAND): find (65.2%) or aggregate (5.9%) above 100 ms, or a getMore batch of an export (0.13%) | 71.3% of lines | database |
| 22943 | Connection accepted (NETWORK): new client connection with the open-connection count | 5.9% of lines | database |
| 51800 | client metadata (NETWORK): driver handshake document of the connection | 5.9% of lines | database |
| 22944 | Connection ended (NETWORK): connection closed with the open-connection count | 5.9% of lines | database |
| 5286306 | Successfully authenticated (ACCESS): SCRAM-SHA-256 login succeeded | 5.4% of lines | database |
| 6788700 | Received first command on ingress connection (NETWORK): first command after the login, with the delay | 5.4% of lines | database |
| 5286307 | Failed to authenticate (ACCESS): wrong password, AuthenticationFailed (18) | 0.03% of lines | database |
Realism Features
- Top-level order t, s, c, id, ctx, msg, attr with the formatter padding (s to 5, c to 11, id to 8 characters), no svc field, t.$date in the server time zone with milliseconds, and each message attribute order taken from the r7.0.43 log sites. The ECS fields mirror the Elastic mongodb 1.24 pipeline; event.created and event.ingested follow the line by a few hundred milliseconds to seconds.
- About 39,000 lines a day (±3% day to day) on a UTC hour curve: 0.70 lines/s at 08-19, 0.40 at 07-08 and 19-21 and 0.20 at 21-07, with no weekly cycle. Service traffic makes up about 91% of the lines. People open about one session per person per hour at 08-18, 0.4 of that at 07-08 and 18-19 and 0.05 at night; the billing worker connects about every 25 minutes in the day and less often at night, and the reporting job runs about five times a day at any hour.
- orders-api (four instances, six pooled connections each), catalog-service (two instances, four each) and mongodb_exporter keep pooled connections; an idle pooled connection closes after a median 13 minutes (the exporter's after about two hours) and reopens on demand a median 15 s later. Two DBAs (mongosh) and two analysts (MongoDB Compass) run about 11 sessions each a day with a median of 4 reads and 40 s think time; together they export about 12 times a day (crm.customers about 8), the reporting job about 4 times.
- About 16% of people's logins fail (about 8 a day across the four): mistyped attempts, outdated remembered passwords, retries after a median 9 s and give-ups. A single failure before a success is the most common, and three or more happen about six times a week. A service instance that still holds a rotated secret fails 1 to 12 times in a row before it connects, about 1.5 times a day; over all logins 0.55% fail.
- A connection's client metadata follows its Connection accepted a median 1.0 s later in the day (90th percentile 3.3 s) and 2.6 s at night (9.6 s); logins, first commands and export batches are spaced the same way, so the gaps between their timestamps are longer than durationMillis and elapsedMillis imply. Connection ids continue from a high counter, connectionCount follows every accept and end, and the pools are already open when the log starts, so some Connection ended lines close connections accepted earlier.
- Byte form comes from the tagged formatter and log-site source; no raw 7.0 line of these ids was found, and the padding style is confirmed by the 4.4.4 fixture of the Elastic integration. Query shapes, queryHash and planCacheKey, durations, lock counts, storage reads, cpuNanos and driver versions are synthetic, and speculative authentication is assumed for every client.
- TLS, load balancer, replica-set, sharding, startup and shutdown messages, writes, errors other than a wrong password and the Enterprise audit log are not modelled, and service pools do not restart. With anomaly_mode true, counts of failure runs followed by a success and of single-batch customer exports are about one per episode higher than in background.
Sample Output
{
"@timestamp": "2026-09-21T14:12:10.799Z",
"data_stream": {
"dataset": "mongodb.log",
"namespace": "default",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"event": {
"category": [
"database"
],
"created": "2026-09-21T14:12:11.330Z",
"dataset": "mongodb.log",
"ingested": "2026-09-21T14:12:11.867Z",
"kind": "event",
"module": "mongodb",
"original": "{\"t\":{\"$date\":\"2026-09-21T14:12:10.799+00:00\"},\"s\":\"I\", \"c\":\"COMMAND\", \"id\":51803, \"ctx\":\"conn89847\",\"msg\":\"Slow query\",\"attr\":{\"type\":\"command\",\"ns\":\"crm.customers\",\"appName\":\"MongoDB Compass\",\"command\":{\"getMore\":6208691475638660086,\"collection\":\"customers\",\"lsid\":{\"id\":{\"$uuid\":\"c25abd1e-cf0c-432c-bbd3-4a051fc380cb\"}},\"$db\":\"crm\"},\"originatingCommand\":{\"find\":\"customers\",\"filter\":{\"address.region\":\"far-east\"},\"lsid\":{\"id\":{\"$uuid\":\"c25abd1e-cf0c-432c-bbd3-4a051fc380cb\"}},\"$db\":\"crm\"},\"planSummary\":\"COLLSCAN\",\"cursorid\":6208691475638660086,\"keysExamined\":0,\"docsExamined\":116411,\"nBatches\":1,\"cursorExhausted\":true,\"numYields\":103,\"nreturned\":5997,\"queryFramework\":\"classic\",\"reslen\":12257781,\"locks\":{\"FeatureCompatibilityVersion\":{\"acquireCount\":{\"r\":104}},\"Global\":{\"acquireCount\":{\"r\":104}}},\"storage\":{\"data\":{\"bytesRead\":206906,\"timeReadingMicros\":7900}},\"cpuNanos\":106188935,\"remote\":\"10.30.2.50:50368\",\"protocol\":\"op_msg\",\"durationMillis\":150}}",
"type": [
"info"
]
},
"host": {
"name": "mongo-01.corp.example"
},
"input": {
"type": "logfile"
},
"log": {
"file": {
"path": "/var/log/mongodb/mongod.log"
},
"level": "I"
},
"message": "Slow query",
"mongodb": {
"log": {
"attr": {
"type": "command",
"ns": "crm.customers",
"appName": "MongoDB Compass",
"command": {
"getMore": 6208691475638660086,
"collection": "customers",
"lsid": {
"id": {
"$uuid": "c25abd1e-cf0c-432c-bbd3-4a051fc380cb"
}
},
"$db": "crm"
},
"originatingCommand": {
"find": "customers",
"filter": {
"address.region": "far-east"
},
"lsid": {
"id": {
"$uuid": "c25abd1e-cf0c-432c-bbd3-4a051fc380cb"
}
},
"$db": "crm"
},
"planSummary": "COLLSCAN",
"cursorid": 6208691475638660086,
"keysExamined": 0,
"docsExamined": 116411,
"nBatches": 1,
"cursorExhausted": true,
"numYields": 103,
"nreturned": 5997,
"queryFramework": "classic",
"reslen": 12257781,
"locks": {
"FeatureCompatibilityVersion": {
"acquireCount": {
"r": 104
}
},
"Global": {
"acquireCount": {
"r": 104
}
}
},
"storage": {
"data": {
"bytesRead": 206906,
"timeReadingMicros": 7900
}
},
"cpuNanos": 106188935,
"remote": "10.30.2.50:50368",
"protocol": "op_msg",
"durationMillis": 150
},
"component": "COMMAND",
"context": "conn89847",
"id": 51803
}
},
"tags": [
"preserve_original_event"
]
}Parameters
| Parameter | Default | Description |
|---|---|---|
| db_host | mongo-01.corp.example | Server host name in host.name; ASCII letters, digits, dot and hyphen |
| log_timezone | +00:00 | Server time zone offset written in t.$date, [+-]HH:MM; the hour curves stay in UTC |
| anomaly_interval_hours | 24 | Episode interval in hours of source time, number from 6 to 8,760 |
| anomaly_mode | true | true adds episodes to background, false produces background only |
Related Generators
Microsoft SQL Server Audit
SQL Server Audit via Windows Event ID 33205 — login/logout lifecycle, DML queries (SELECT/INSERT/UPDATE/DELETE), stored procedure execution, schema changes (CREATE/ALTER/DROP), permission management (GRANT/DENY/REVOKE), role membership, backups, DBCC commands, and password changes.
MySQL Audit
MySQL Enterprise Audit Plugin events (ECS-compatible JSON) covering all four audit classes — connection, general, table_access, and audit. Generates connect/disconnect lifecycle, DML queries (SELECT/INSERT/UPDATE/DELETE), table access tracking, DDL schema changes, GRANT/REVOKE privileges, admin commands, query errors, and failed authentication attempts with realistic query statistics.
PostgreSQL Audit Logs
PostgreSQL with pgAudit — SELECT/INSERT/UPDATE/DELETE queries with parameterized statements, connection lifecycle, authentication failures, DDL operations, role management (GRANT/REVOKE), and database errors (deadlocks, constraint violations).