Aruba ClearPass Policy Manager
ClearPass 6.11 administrative audit records in ECS JSON, with a ClearPass-like RFC 5424 syslog message in event.original, for testing detections on administrator logins and configuration changes. About 300 records a day from twelve administrators on a UTC working-day curve. Recurring episodes show a guessed administrator password followed by weakened logging and a new SSH key.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/identity-aruba-clearpass/generator.yml \
--id clearpass \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| Logged in / None | WebUI administrator login | 38.5% background share | authentication |
| Account Settings / MODIFY | Account settings modification | 21.1% background share | configuration |
| Cluster-wide Parameter / MODIFY | Cluster-wide parameter modification | 18.5% background share | configuration |
| Log Service Configuration / MODIFY | Log service configuration modification | 11.1% background share | configuration |
| SSH Public Key / ADD | SSH public key addition | 8.8% background share | configuration |
| Login Failed / None | Failed WebUI administrator login | 2.1% background share | authentication |
Realism Features
- About 300 audit records a day on a UTC working-day curve: about 2 an hour at night, rising to about 36 an hour around 12:00, with a daily variation of about 3%. Every day of the week looks alike.
- Twelve administrators, including the built-in admin_user account, open WebUI sessions at their own steady rates, one session at a time. About 12% of sessions are maintenance work on logging and CLI access, mostly from a shared jump host; routine sessions come from the administrator's desk, one of two VPN addresses or the jump host and mostly change account settings and cluster parameters. A session makes one to eight changes minutes apart; some routine sessions only log in.
- Failed logins are about 5% of login attempts. 1% of logins from a desk, 2% from a VPN laptop and 6% from the jump host start with one to five mistyped passwords a few seconds apart. Each administrator changes the password about every 45 days; one of their clients keeps the old saved password for about a day and retries it three to seven times about half a minute apart before the new one is typed, or gives up. About every other day, an address from the documentation ranges tries one to six passwords for admin_user or another administrator, without success.
- The profile is the Audit Records export template with RFC 5424 explicitly selected; ClearPass defaults to Standard/raw export. The eventId, native action, category, field names and representative values follow Aruba's 6.11 auditable-event examples. ECS @timestamp follows the inner audit time, the later export time is kept as clearpass.export_timestamp, and WebUI descriptions keep the vendor's literal backslash-n separators.
- Configuration records carry the native User but no client IP or login session ID, so their association with a login is only by user, node and time; a rule keyed on the account can join an episode's changes to an ordinary failed-then-successful login of the same account shortly before it.
- The full native Audit Records RFC 5424 message has not been compared with a real export: Aruba's audit examples omit <PRI>1 and its published <151>1 message is for Session Logs, so priority 151 is an assumption. Process ID, message ID progression, the 6-31 second export delay, session IDs, names, addresses and the activity mix are modeled. One node and six audit classes are covered, and every login uses the Super Administrator role.
- Delivered live, a record arrives after its own audit timestamp: about two minutes later at the median, within 20 minutes for 90% of records, and up to several hours for sessions that start during quiet hours; episode records arrive up to about 30 minutes late.
Sample Output
{
"@timestamp": "2026-09-02T15:31:34.441Z",
"clearpass": {
"action": "None",
"audit_timestamp": "2026-09-02T15:31:34.441Z",
"category": "Logged in",
"component": "Policy Manager UI",
"description": "User: platform-admin\\nRole: Super Administrator\\nAuthentication Source: Policy Manager Local Admin Users\\nSession ID: cd5726be9347be2a593fb506b33f7119\\nClient IP Address: 10.8.2.232\\nSession Inactive Expiry Time: 359 mins",
"event_id": 3003,
"export_timestamp": "2026-09-02T15:31:51.338Z",
"level": "INFO",
"message_id": "1178-1-0",
"process_id": 31154,
"software_version": "6.11.11.261850",
"syslog_priority": 151
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "login-success",
"category": [
"authentication"
],
"dataset": "clearpass.audit",
"kind": "event",
"original": "<151>1 2026-09-02T15:31:51.338Z 10.20.0.10 ClearPass 31154 1178-1-0 [timeQuality tzKnown=\"1\"][origin swVersion=\"6.11.11.261850\" software=\"PolicyManager\" ip=\"10.20.0.10\" enterpriseId=\"1.3.6.1.4.1.14823\"][clearPass@14823 eventId=\"3003\" Action=\"None\" Category=\"Logged in\" Description=\"User: platform-admin\\nRole: Super Administrator\\nAuthentication Source: Policy Manager Local Admin Users\\nSession ID: cd5726be9347be2a593fb506b33f7119\\nClient IP Address: 10.8.2.232\\nSession Inactive Expiry Time: 359 mins\" Level=\"INFO\" Component=\"Policy Manager UI\" CppmNode.CPPM-Node=\"10.20.0.10\" Timestamp=\"2026-09-02T15:31:34.441Z\"]",
"outcome": "success",
"type": [
"start"
]
},
"host": {
"ip": [
"10.20.0.10"
],
"name": "10.20.0.10"
},
"related": {
"ip": [
"10.8.2.232"
],
"user": [
"platform-admin"
]
},
"source": {
"ip": "10.8.2.232"
},
"user": {
"name": "platform-admin"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the recurring anomaly episodes to the background; false keeps only background activity |
| anomaly_interval_hours | 24 | Hours from one episode start to the next due time, 3 to 8,760 |
| node_ip | 10.20.0.10 | ClearPass node and syslog hostname; also fixes the administrator organisation |
| admin_user | admin | Name of the built-in administrator account; must differ from the names in samples/admins.json |
| software_version | 6.11.11.261850 | Documented 6.11 example version in origin |
| syslog_priority | 151 | Synthetic RFC 5424 priority; verify against an Audit Records capture |
Related Generators
Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.