Hub
Identity

FreeRADIUS Linelog Authentication and Accounting

FreeRADIUS 3.2.10 file linelog output of one server authenticating 802.1X wireless clients of one controller: Accepted user and Rejected user lines from an explicitly configured linelog instance and tagged accounting Connect and Disconnect lines, as ECS JSON with the verbatim line in event.original. About 27,800 lines a day from 1,000 devices of 726 users on 30 access points. Recurring episodes show password guessing from a device's usual station that succeeds and opens a network session.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/identity-freeradius/generator.yml \
  --id freeradius \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
acceptAccepted user: line of the auth_siemaudit instance31.8% of linesauthentication
connectConnect: accounting Start line, a few seconds after an accept31.2% of linessession
disconnectDisconnect: accounting Stop line with the actual session seconds31.2% of linessession
rejectRejected user: line of the auth_siemaudit instance5.7% of linesauthentication

Realism Features

  • The authentication lines require the explicit auth_siemaudit linelog instance and post-auth calls shown in the README, because built-in log.auth is off and the default linelog authentication messages carry only the user name; the accounting lines follow the tagged log_accounting Start and Stop formats verbatim. Authentication and accounting go to two files, and the station IDs use the RFC 3580 form with :SSID after the access-point MAC. Interim-Update, Accounting-On/Off and Access-Challenge lines are not generated.
  • The site has 726 users with 1,000 client devices (274 users carry a laptop and a phone) and 30 access points of one SSID. Each device has its own activity level, within a factor of four of the others, and one to three preferred neighbouring access points; it has at most one attempt or session at a time, a fixed framed IP lease and a new NAS-Port association ID for each attempt.
  • Volume is about 27,800 lines a day on a fixed UTC hour curve: 0.06 lines/s from 00:00 to 05:00, rising through 06:00-08:00 to 0.6 lines/s from 08:00 to 16:00, then tapering hour by hour to 0.08 lines/s at 23:00. The daily total varies by about 2%, and up to about 690 sessions are open at the same time in office hours.
  • 93.5% of attempts succeed at once, with the accounting Start a median 3 s after the accept; 5% start with one to eight mistyped passwords a few seconds apart, each extra reject half as likely as the previous count, and 15% of these users give up; 1.5% come from a device with a stale saved password rejected 2 to 14 times about every 20 minutes until it is updated; 1.5% of accepts have no accounting Start. Sessions last about 12 minutes, 36 minutes and 1.8 hours at the 10th, 50th and 90th percentile, at most about 12 hours. All rates are synthetic, not measured FreeRADIUS statistics.
  • An accept that follows five or more rejects of its user and station within ten minutes (about 25 a day) is never followed by an accounting Start in ordinary traffic, while other accepts miss their Start only 1.5% of the time; a detector with a lower threshold or a longer window also matches ordinary near misses. With anomaly_mode true, runs of five or more rejects and such runs followed by an accept are about one per episode more frequent: about seven more a week at the default interval, on top of roughly 175 such runs a week.
  • event.original and message hold the bare file line without a syslog header; @timestamp, host.name and radius.client_shortname are collector enrichment. The selected formats carry no Acct-Session-Id, so a session is the Start/Stop pair of one station. The ECS layout is inferred. No raw output from a running FreeRADIUS 3.2.10 server was available, the custom authentication instance was not exercised on a daemon, and compatibility with syslog-oriented FreeRADIUS parsers is not claimed. One server, controller and SSID, with no roaming, Interim-Update or NAS reboots; the hour curve repeats every day with no weekday cycle, and at night an accounting Start can follow its accept by up to about three minutes.

Sample Output

{
  "@timestamp": "2026-09-04T08:18:12.849+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "connect",
    "category": [
      "session"
    ],
    "dataset": "freeradius.linelog",
    "kind": "event",
    "module": "freeradius",
    "original": "Connect: [matvey.titov] (did 06-1B-2C-41-2F-95:corp-wifi cli 02-4C-1A-7E-8C-C3 port 224 ip 10.50.7.129)",
    "outcome": "success",
    "type": [
      "start"
    ]
  },
  "host": {
    "name": "radius-01"
  },
  "message": "Connect: [matvey.titov] (did 06-1B-2C-41-2F-95:corp-wifi cli 02-4C-1A-7E-8C-C3 port 224 ip 10.50.7.129)",
  "radius": {
    "acct_status_type": "Start",
    "called_station_id": "06-1B-2C-41-2F-95:corp-wifi",
    "calling_station_id": "02-4C-1A-7E-8C-C3",
    "client_shortname": "wlc-01",
    "framed_ip_address": "10.50.7.129",
    "nas_port": 224
  },
  "service": {
    "name": "radiusd"
  },
  "source": {
    "ip": "10.50.7.129",
    "mac": "02-4C-1A-7E-8C-C3"
  },
  "user": {
    "name": "matvey.titov"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueEmit recurring episodes; false gives background only
anomaly_interval_hours24Hours from one episode start to the next due time, 2 to 720; a value outside fails the render
radius_hostradius-01host.name enrichment
nas_clientwlc-01radius.client_shortname enrichment, the controller's clients.conf short name
ssidcorp-wifiSSID appended to the access-point MAC in Called-Station-Id

Related Generators