Hub
Identity

OpenLDAP auditlog

About 1,980 successful directory changes per day, with native multiline LDIF and a custom ECS wrapper.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/identity-openldap-auditlog/generator.yml \
  --id openldap \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
modify:attributesPerson description, telephone, title or mailAbout 86%iam
modify:userPasswordPassword replacementAbout 5%iam
modify:memberGroup membership addition or removalAbout 6%iam
addTemporary service account creationAbout 2%iam
deleteExpired service account deletionAbout 2%iam

Realism Features

  • Three administrators and ordinary provisioning throughout the day
  • Temporary accounts and their memberships expire after two to four hours
  • Bind, search and failed-operation logs are outside this feed

Sample Output

{
  "@timestamp": "2026-09-20T01:26:42.938437+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "ldap-add",
    "category": [
      "iam"
    ],
    "kind": "event",
    "original": "# add 1789867602 dc=corp,dc=example uid=svc-maint,ou=People,dc=corp,dc=example IP=10.24.1.11:46066 conn=1012\ndn: uid=svc-worker-000001,ou=People,dc=corp,dc=example\nchangetype: add\nobjectClass: top\nobjectClass: person\nobjectClass: organizationalPerson\nobjectClass: inetOrgPerson\nuid: svc-worker-000001\ncn: Service Account svc-worker-000001\nsn: Service\nuserPassword: {SSHA}6W3S5Qd7mfKOi9XaQIvaLxOeyv0wMDAwMDA4Nw==\nstructuralObjectClass: inetOrgPerson\nentryUUID: 94eb35b2-ea54-4956-bd14-4f22ba691e8f\ncreatorsName: uid=svc-maint,ou=People,dc=corp,dc=example\ncreateTimestamp: 20260920012642Z\nentryCSN: 20260920012642.938437Z#000000#000#000000\nmodifiersName: uid=svc-maint,ou=People,dc=corp,dc=example\nmodifyTimestamp: 20260920012642Z\n# end add 1789867602\n\n",
    "outcome": "success",
    "type": [
      "creation"
    ]
  },
  "host": {
    "name": "ldap01.corp.example"
  },
  "ldap": {
    "auditlog": {
      "actor_dn": "uid=svc-maint,ou=People,dc=corp,dc=example",
      "attribute": "uid",
      "base_dn": "dc=corp,dc=example",
      "change_type": "add",
      "connection_id": 1012,
      "entry_csn": "20260920012642.938437Z#000000#000#000000",
      "operation": null,
      "peer_ip": "10.24.1.11",
      "peer_port": 46066,
      "target_dn": "uid=svc-worker-000001,ou=People,dc=corp,dc=example",
      "value": "svc-worker-000001"
    }
  },
  "related": {
    "ip": [
      "10.24.1.11"
    ],
    "user": [
      "uid=svc-maint,ou=People,dc=corp,dc=example",
      "uid=svc-worker-000001,ou=People,dc=corp,dc=example"
    ]
  },
  "source": {
    "ip": "10.24.1.11",
    "port": 46066
  },
  "user": {
    "name": "uid=svc-maint,ou=People,dc=corp,dc=example"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueInclude recurring linked sequences
anomaly_interval_hours2Recurrence in hours, minimum 1
host_nameldap01.corp.exampleDirectory server hostname
base_dndc=corp,dc=exampleDirectory suffix
operator_dnuid=svc-maint,ou=People,dc=corp,dc=exampleMaintenance administrator DN
backdoor_uidsvc-backupOne account prefix shared by ordinary work and episodes
privileged_groupdirectory-adminsExisting privileged group

Related Generators