Identity
OpenLDAP auditlog
About 1,980 successful directory changes per day, with native multiline LDIF and a custom ECS wrapper.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/identity-openldap-auditlog/generator.yml \
--id openldap \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| modify:attributes | Person description, telephone, title or mail | About 86% | iam |
| modify:userPassword | Password replacement | About 5% | iam |
| modify:member | Group membership addition or removal | About 6% | iam |
| add | Temporary service account creation | About 2% | iam |
| delete | Expired service account deletion | About 2% | iam |
Realism Features
- Three administrators and ordinary provisioning throughout the day
- Temporary accounts and their memberships expire after two to four hours
- Bind, search and failed-operation logs are outside this feed
Sample Output
{
"@timestamp": "2026-09-20T01:26:42.938437+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "ldap-add",
"category": [
"iam"
],
"kind": "event",
"original": "# add 1789867602 dc=corp,dc=example uid=svc-maint,ou=People,dc=corp,dc=example IP=10.24.1.11:46066 conn=1012\ndn: uid=svc-worker-000001,ou=People,dc=corp,dc=example\nchangetype: add\nobjectClass: top\nobjectClass: person\nobjectClass: organizationalPerson\nobjectClass: inetOrgPerson\nuid: svc-worker-000001\ncn: Service Account svc-worker-000001\nsn: Service\nuserPassword: {SSHA}6W3S5Qd7mfKOi9XaQIvaLxOeyv0wMDAwMDA4Nw==\nstructuralObjectClass: inetOrgPerson\nentryUUID: 94eb35b2-ea54-4956-bd14-4f22ba691e8f\ncreatorsName: uid=svc-maint,ou=People,dc=corp,dc=example\ncreateTimestamp: 20260920012642Z\nentryCSN: 20260920012642.938437Z#000000#000#000000\nmodifiersName: uid=svc-maint,ou=People,dc=corp,dc=example\nmodifyTimestamp: 20260920012642Z\n# end add 1789867602\n\n",
"outcome": "success",
"type": [
"creation"
]
},
"host": {
"name": "ldap01.corp.example"
},
"ldap": {
"auditlog": {
"actor_dn": "uid=svc-maint,ou=People,dc=corp,dc=example",
"attribute": "uid",
"base_dn": "dc=corp,dc=example",
"change_type": "add",
"connection_id": 1012,
"entry_csn": "20260920012642.938437Z#000000#000#000000",
"operation": null,
"peer_ip": "10.24.1.11",
"peer_port": 46066,
"target_dn": "uid=svc-worker-000001,ou=People,dc=corp,dc=example",
"value": "svc-worker-000001"
}
},
"related": {
"ip": [
"10.24.1.11"
],
"user": [
"uid=svc-maint,ou=People,dc=corp,dc=example",
"uid=svc-worker-000001,ou=People,dc=corp,dc=example"
]
},
"source": {
"ip": "10.24.1.11",
"port": 46066
},
"user": {
"name": "uid=svc-maint,ou=People,dc=corp,dc=example"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include recurring linked sequences |
| anomaly_interval_hours | 2 | Recurrence in hours, minimum 1 |
| host_name | ldap01.corp.example | Directory server hostname |
| base_dn | dc=corp,dc=example | Directory suffix |
| operator_dn | uid=svc-maint,ou=People,dc=corp,dc=example | Maintenance administrator DN |
| backdoor_uid | svc-backup | One account prefix shared by ordinary work and episodes |
| privileged_group | directory-admins | Existing privileged group |
Related Generators
Identity
Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
Identity
Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
Identity
ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.