Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/identity-keycloak/generator.yml \
--id keycloak \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| LOGIN | Browser login to an OIDC client | 39.26% share (39.11-39.25% without anomalies) | authentication |
| CODE_TO_TOKEN | Authorization-code exchange after LOGIN | 39.21% share (39.07-39.22% without anomalies) | authentication |
| LOGOUT | Logout of a session (30% of user sessions, 50% of admin console sessions) | 11.67% share (11.70-11.85% without anomalies) | authentication |
| LOGIN_ERROR | invalid_user_credentials: wrong passwords before a login and administrators retrying a rotated password over VPN | 9.47% share (9.29-9.59% without anomalies) | authentication |
| CREATE-REALM_ROLE_MAPPING | Realm role granted to a user in the admin console | 0.22% share (0.18-0.25% without anomalies) | iam |
| DELETE-REALM_ROLE_MAPPING | Realm role removed, including expiry of time-bound secops-admin grants | 0.17% share (0.16-0.20% without anomalies) | iam |
Realism Features
- One realm with 1,500 users and 5 administrators. Users log in to one to three OIDC clients, 7.7 times a day on average; administrators log in 12 times a day, to security-admin-console (85%) or account-console, grant and remove realm roles, and connect over VPN for 40-50% of their attempts. Addresses are the account's workstation or one of three VPN egress addresses shared by all remote staff. Rates are synthetic, not a vendor-published distribution.
- About 29,000 events a day with ±10% day-to-day variation on a UTC hour-of-day curve: 0.60 events/s in 08-18, 0.30 in 07-08 and 18-20, 0.15 in 20-23 and 0.09 in 23-07. The curve repeats every day, so weekends look like weekdays.
- Records of one login are seconds apart rather than milliseconds: wrong passwords a median 12 s apart, CODE_TO_TOKEN a median 2.8 s after LOGIN (9 s at night) and never more than 55 s, within Keycloak's one-minute Client Login Timeout. About 0.1% of LOGINs, nearly all at night, have no code exchange because the code expired.
- 12% of login attempts start with 1-8 wrong passwords and 15% of those give up. Administrator passwords are rotated by a vault: over VPN an administrator sometimes types the previous one 3-8 times before fetching the new one (7% of VPN admin console attempts, 45% of those right after such an attempt), and about 90% then log in and continue their console work. These retries cluster by administrator and day.
- Every chain element occurs in ordinary traffic in both modes: each administrator + VPN address pair logs in at least three times a week, administrator bursts of five or more wrong passwords from a VPN address happen about 11 times a week (roughly 3 to 19), most followed by a login and often by a role grant within 15 minutes, and secops-admin is granted 8-12 times a day. Every secops-admin grant is time-bound and removed after a lease (median 8 h), typically 5-30 hours later. Each episode adds one such burst, about six more a week at the default interval, so a single week with anomalies usually looks like a busy background week; a 12-hour interval doubles the excess.
- Listener profile: success-level=info (the default is debug), include-representation=true and realm admin event details enabled. With the defaults, successful events are not written at INFO and admin lines carry no representation. LOGIN and CODE_TO_TOKEN detail keys copy a raw Keycloak 26 log; no 26.x raw LOGIN_ERROR with the full detail set or raw LOGOUT was available, so those keys follow the Elastic fixture, a 26.0.7 raw line and the listener source. Keycloak stores details in a HashMap, so key order in a real deployment can differ; role representation keys follow RoleRepresentation and the exact body depends on the admin client.
- Only one realm and these event types are modeled: no refresh-token, client-credentials, required-action, brute-force lockout, code-exchange error or user/group admin events. event.ingested lags 0.3-20 s and log file rotation is not modeled.
Sample Output
{
"@timestamp": "2026-09-01T03:40:38.276Z",
"agent": {
"ephemeral_id": "e026770f-355a-4130-97ba-658b5a1f98f2",
"id": "a0634c5c-35db-4f7a-8273-73052fa14208",
"name": "keycloak-01.corp.example",
"type": "filebeat",
"version": "8.17.0"
},
"data_stream": {
"dataset": "keycloak.log",
"namespace": "default",
"type": "logs"
},
"ecs": {
"version": "8.11.0"
},
"elastic_agent": {
"id": "a0634c5c-35db-4f7a-8273-73052fa14208",
"snapshot": false,
"version": "8.17.0"
},
"event": {
"action": "CREATE-REALM_ROLE_MAPPING",
"agent_id_status": "verified",
"category": [
"iam"
],
"code": "CREATE-REALM_ROLE_MAPPING",
"dataset": "keycloak.log",
"ingested": "2026-09-01T03:40:41Z",
"kind": "event",
"original": "2026-09-01 03:40:38,276 INFO [org.keycloak.events] (executor-thread-46) operationType=\"CREATE\", realmId=\"523dd4a1-c4d0-4cf1-acb4-ea0f1de7e9c4\", realmName=\"corp\", clientId=\"3f1c9b52-8d47-4e0a-b6d2-71a95c0e4f83\", userId=\"4dc163fa-d66b-46b2-b00c-ac3390f7f3a4\", ipAddress=\"10.20.200.11\", resourceType=\"REALM_ROLE_MAPPING\", resourcePath=\"users/e7ec4496-f5dd-48a4-8fbd-ddb322908061/role-mappings/realm\", representation=\"[{\\\"id\\\":\\\"b18f4680-7b51-450e-89f2-65d98024e7b7\\\",\\\"name\\\":\\\"secops-admin\\\",\\\"composite\\\":false,\\\"clientRole\\\":false,\\\"containerId\\\":\\\"523dd4a1-c4d0-4cf1-acb4-ea0f1de7e9c4\\\"}]\"",
"outcome": "unknown",
"timezone": "+00:00",
"type": [
"info",
"admin",
"creation"
]
},
"host": {
"architecture": "x86_64",
"containerized": true,
"hostname": "keycloak-01.corp.example",
"ip": [
"10.20.1.15"
],
"name": "keycloak-01.corp.example",
"os": {
"codename": "bookworm",
"family": "debian",
"kernel": "6.1.0-28-amd64",
"name": "Debian GNU/Linux",
"platform": "debian",
"type": "linux",
"version": "12"
}
},
"input": {
"type": "filestream"
},
"keycloak": {
"admin": {
"operation": "CREATE",
"resource": {
"path": "users/e7ec4496-f5dd-48a4-8fbd-ddb322908061/role-mappings/realm",
"type": "REALM_ROLE_MAPPING"
}
},
"client": {
"id": "3f1c9b52-8d47-4e0a-b6d2-71a95c0e4f83"
},
"event_type": "admin",
"realm": {
"id": "523dd4a1-c4d0-4cf1-acb4-ea0f1de7e9c4"
}
},
"log": {
"file": {
"path": "/opt/keycloak/data/log/keycloak.log"
},
"level": "INFO",
"logger": "org.keycloak.events",
"offset": 9512095
},
"process": {
"thread": {
"name": "executor-thread-46"
}
},
"related": {
"ip": [
"10.20.200.11"
],
"user": [
"4dc163fa-d66b-46b2-b00c-ac3390f7f3a4",
"e7ec4496-f5dd-48a4-8fbd-ddb322908061"
]
},
"source": {
"address": "10.20.200.11",
"ip": "10.20.200.11"
},
"tags": [
"preserve_original_event",
"forwarded",
"keycloak-log"
],
"user": {
"id": "4dc163fa-d66b-46b2-b00c-ac3390f7f3a4",
"target": {
"id": "e7ec4496-f5dd-48a4-8fbd-ddb322908061"
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Emit recurring anomaly episodes; false gives background only |
| anomaly_interval_hours | 24 | Source-time interval between episodes, 6 to 720 |
| realm | corp | Realm name |
| realm_id | 523dd4a1-c4d0-4cf1-acb4-ea0f1de7e9c4 | Realm id, also the role containerId |
| sso_base_url | https://sso.corp.example | Keycloak base URL used in account-console and admin console redirect URIs |
| admin_console_client_uuid | 3f1c9b52-8d47-4e0a-b6d2-71a95c0e4f83 | Internal id of security-admin-console, logged as clientId of admin events |
| privileged_role_name | secops-admin | Privileged realm role granted by the chain |
| privileged_role_id | b18f4680-7b51-450e-89f2-65d98024e7b7 | Id of that role |
| vpn_nat_ips | [10.20.200.10, 10.20.200.11, 10.20.200.12] | VPN egress addresses shared by remote staff |
| hostname | keycloak-01.corp.example | Keycloak host and agent name |
| host_ip | 10.20.1.15 | Keycloak host address |
| collector_id | a0634c5c-35db-4f7a-8273-73052fa14208 | Elastic Agent id |
| collector_ephemeral_id | e026770f-355a-4130-97ba-658b5a1f98f2 | Elastic Agent ephemeral id |
| collector_version | 8.17.0 | Elastic Agent version |
Related Generators
Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.
Cisco ISE 3.4 Administrative Audit Syslog
Cisco ISE CISE_Administrative_and_Operational_Audit remote syslog and matching ECS-style JSON for one Policy Administration Node, with the complete syslog record in event.original, for detections on ISE administrator activity. Logins, logoffs and failed logins of five administrators and 120 read-only operators, and logging-configuration changes; not RADIUS or TACACS traffic. Weekly episodes show an administrator account taken over by password guessing and used to switch off log forwarding.