Delinea Secret Server CEF
SECRET - VIEW audit records that one Delinea Secret Server 11.3 instance (formerly Thycotic) sends to a syslog/CEF collector, as ECS JSON with the syslog line in event.original, for training SIEM content on privileged credential access. About 12,700 views a day by 240 people on UTC office hours and 4 automation accounts on fixed schedules. Recurring episodes show one administrator viewing five distinct Tier 0 credentials within half an hour.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/identity-delinea-secret-server/generator.yml \
--id delinea-ss \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| Service Desk | SECRET - VIEW by service desk and administrators | ~32% | iam |
| Personal folders | SECRET - VIEW in a personal folder, named after the person, by its owner | ~25% | iam |
| Applications | SECRET - VIEW by DevOps, automation accounts, DBAs and administrators | ~22% | iam |
| Databases | SECRET - VIEW by DBAs, DevOps, administrators and backup automation | ~8% | iam |
| Network Devices | SECRET - VIEW by network engineers, administrators and configuration backup automation | ~8% | iam |
| Tier 0 - Infrastructure | SECRET - VIEW by administrators, occasionally network engineers | ~5% | iam |
Realism Features
- Every record is SECRET - VIEW (CEF class 10004). The CEF header keeps the historical Thycotic Software vendor name of this version, and the JSON mirrors the document the Elastic Thycotic Secret Server integration produces from the line; agent, data stream and ingest fields and cef.* are omitted.
- People account for about 12,000 views a day on UTC office hours: about 0.25 views/s 07:00-17:00, 0.11/s 17:00-21:00 and 0.04/s at night, with 3% day-to-day variation. Each of the 240 people has a fixed ID, one workstation address and a fixed activity weight of 0.4-2.5 times the average, so some open secrets far more often than others. By account: service desk 42%, DevOps 24%, network engineers 11%, administrators 9%, DBAs 9%, automation 5%.
- Ordinary sessions hold 1-6 views about 40 s apart; each view re-opens the previous secret (30%) or picks a folder by role and a secret by its fixed popularity. A quarter of administrator sessions are infrastructure work of 2-9 views about 35 s apart, 85% of them Tier 0: an administrator views about 20-25 Tier 0 secrets a day on average, and four distinct Tier 0 secrets by one administrator within 30 minutes occur about 30-40 times a day.
- Automation accounts fetch about 660 secrets a day at any hour, each run in the same order within one second: svc.jenkins 2 application secrets every 10 minutes, svc.zabbix its monitoring API credential every 5 minutes, svc.ansible 3 application secrets at minute 05 of every hour and 6 network device credentials at 01:30, svc.backup 3 database credentials at 22:00.
- The syslog header carries the send time, a log-normal delay (median 3 s) after the event time rt, as in the Elastic fixture. Outside episodes no user views five distinct Tier 0 secrets within 30 minutes of rt: a user who viewed four distinct ones in the last 30 minutes re-opens the latest of them instead (about 30-50 such views a day).
- Each episode adds 5-15 Tier 0 views by its administrator, who opens no Tier 0 secret from the fifth distinct view until the first of the five is 30 minutes old (usually 2-5 minutes); ordinary views in that time go to the administrator's other folders. An episode run holds fewer of the administrator's personal-folder views than an ordinary run of four or more distinct Tier 0 secrets (about 0.3 against 0.7 per run).
- Only SECRET - VIEW is generated: other 11.3 event layouts are not published. Day padding in the header and rt is unconfirmed by the fixture, only the legacy rt DateTime format is modelled, and clocks are UTC with second resolution. Users, secrets, folders, IDs, rates, schedules and the office-hours curve are an assumed large organisation, not measured production data; consecutive views in one session are a median of about 50 s apart, wider at night, and weekends are not modelled.
Sample Output
{
"@timestamp": "2026-09-27T14:57:14.000Z",
"ecs": {
"version": "8.11.0"
},
"event": {
"action": "view",
"category": [
"iam"
],
"code": "10004",
"dataset": "thycotic_ss.logs",
"kind": "event",
"original": "Sep 27 14:57:14 SECRET-SRV-01 CEF:0|Thycotic Software|Secret Server|11.3.000001|10004|SECRET - VIEW|2|msg=[[SecretServer]] Event: [Secret] Action: [View] By User: M.Mccarthy Item Name: ESXi root - esx-cl01 (Item Id: 5781) Container Name: Tier 0 - Infrastructure (Container Id: 162) suid=2926 suser=M.Mccarthy cs4=Michael Mccarthy cs4Label=suser Display Name src=10.20.5.145 rt=Sep 27 2026 14:57:06 fname=ESXi root - esx-cl01 fileType=Secret fileId=5781 cs3Label=Folder cs3=Tier 0 - Infrastructure",
"provider": "secret",
"type": [
"info"
]
},
"host": {
"name": "SECRET-SRV-01"
},
"message": "[[SecretServer]] Event: [Secret] Action: [View] By User: M.Mccarthy Item Name: ESXi root - esx-cl01 (Item Id: 5781) Container Name: Tier 0 - Infrastructure (Container Id: 162)",
"observer": {
"hostname": "SECRET-SRV-01",
"product": "Secret Server",
"vendor": "Thycotic Software",
"version": "11.3.000001"
},
"related": {
"hosts": [
"SECRET-SRV-01"
],
"ip": [
"10.20.5.145"
],
"user": [
"M.Mccarthy"
]
},
"source": {
"ip": "10.20.5.145"
},
"thycotic_ss": {
"event": {
"secret": {
"folder": "Tier 0 - Infrastructure",
"id": "5781",
"name": "ESXi root - esx-cl01"
},
"time": "2026-09-27T14:57:06.000Z"
}
},
"user": {
"full_name": "Michael Mccarthy",
"id": "2926",
"name": "M.Mccarthy"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add periodic episodes to ordinary activity; false produces ordinary activity only |
| anomaly_interval_hours | 24 | Episode interval in hours of event time, 2-8760 |
| server_host | SECRET-SRV-01 | Syslog hostname, host.name and observer.hostname |
| device_version | 11.3.000001 | Version in the CEF header; the record layout is confirmed for this version only |
| domain | contoso | Domain prefix in personal admin account and breakglass secret names |
Related Generators
Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.