Hub
Messaging

Apache Kafka StandardAuthorizer Denial Log

Kafka 3.9.0 KRaft StandardAuthorizer denials of topic operations by misconfigured clients retrying requests they are not allowed to make, as native kafka-authorizer.log lines with parsed ECS and kafka.* fields. About 5,100-5,200 denials a day from twelve SASL principals, around the clock with a daytime rise. Recurring episodes deny one principal four different operations on one topic within minutes.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/messaging-apache-kafka-authorizer/generator.yml \
  --id kafka-authorizer \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
READDenied consumer Fetch, authorized by the broker55.4-56.5% of records per dayapi
WRITEDenied Produce, authorized by the broker38.9-40.2% of records per dayapi
ALTER_CONFIGSDenied AlterConfigs, forwarded to the controller2.4-3.0% of records per dayapi
DELETEDenied DeleteTopics, forwarded to the controller2.0-2.2% of records per dayapi

Realism Features

  • One combined KRaft broker/controller, twelve SASL User principals each bound to one client address, and four existing topics. Clients hold only DESCRIBE ACLs, so every attempt ends in DefaultDeny; application accounts are denied reads and writes, and only the two operations accounts, the analyst and the audit exporter are denied administrative requests.
  • The nine application service accounts produce about 4,500 denials a day (89%), an even floor around the clock plus a broad daytime rise peaking at 11:00-13:00; the analyst and operations accounts produce about 660 a day (11%), 600 of them between 08:00 and 18:00. That is about 130 denials an hour at night and 310-340 at the midday peak (UTC by default), with each day varying by up to 3%.
  • Each client retries one denied request at a time: 1-8 Fetch or Produce attempts, or 1-3 administrative attempts, 24 s apart at the 10th percentile, 58 s in median and 165 s at the 90th. After a run the client tries another operation on the same topic with probability 0.3, in median about 150 s later. 93% of denials follow a denial of the same principal within 10 minutes; consecutive records are 10.6 s apart in median and 99% within 90 s.
  • All 13 native fields (layout time, level and logger plus the ten audit message fields) are generated and parsed; forwarded AlterConfigs and DeleteTopics keep the original client principal and address. Only INFO denials of explicitly requested operations are in this stream; allowed decisions, filter checks, authentication and successful traffic are not. event.created and event.ingested are synthetic collector times.
  • The format is implemented from the tagged Kafka 3.9.0 source and its unit-test expectation, not verified byte for byte against a running broker. Elastic publishes no authorizer sample and its Kafka authentication test log is a different stream, so the ECS mapping is this pack's own. The JVM is assumed to run in UTC; volumes, hour curves and client weights are synthetic, and tight-loop retry floods, other rules (MatchingAcl, SuperUser), other resource types and cluster-level denials are not generated.
  • Episode steps come faster than ordinary operation changes: an episode moves to the next operation after about 15-85 s, while an ordinary client switching operations on one topic does so after about 150 s in median (15-17% within a minute).

Sample Output

{
  "@timestamp": "2026-10-01T14:03:17.180Z",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "authorization-denied",
    "category": [
      "api"
    ],
    "created": "2026-10-01T14:03:17.795Z",
    "ingested": "2026-10-01T14:03:19.008Z",
    "kind": "event",
    "original": "[2026-10-01 14:03:17,180] INFO Principal = User:ops-config is Denied operation = ALTER_CONFIGS from host = 10.40.3.20 on resource = Topic:LITERAL:metrics-internal for request = AlterConfigs with resourceRefCount = 1 based on rule DefaultDeny (kafka.authorizer.logger)",
    "outcome": "failure",
    "timezone": "+00:00",
    "type": [
      "denied"
    ]
  },
  "host": {
    "name": "kafka-01.corp.example"
  },
  "kafka": {
    "authorization_result": "Denied",
    "log": {
      "class": "kafka.authorizer.logger",
      "component": "unknown"
    },
    "operation": "ALTER_CONFIGS",
    "principal": "User:ops-config",
    "request": "AlterConfigs",
    "resource": {
      "name": "metrics-internal",
      "pattern_type": "LITERAL",
      "type": "Topic"
    },
    "resource_ref_count": 1,
    "rule": "DefaultDeny"
  },
  "log": {
    "level": "INFO",
    "logger": "kafka.authorizer.logger"
  },
  "message": "Principal = User:ops-config is Denied operation = ALTER_CONFIGS from host = 10.40.3.20 on resource = Topic:LITERAL:metrics-internal for request = AlterConfigs with resourceRefCount = 1 based on rule DefaultDeny",
  "related": {
    "ip": [
      "10.40.3.20"
    ],
    "user": [
      "ops-config"
    ]
  },
  "source": {
    "ip": "10.40.3.20"
  },
  "tags": [
    "preserve_original_event"
  ],
  "user": {
    "name": "ops-config"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd recurring episodes to the background; false produces only the background
anomaly_interval_hours24Hours between episode starts, 1 to 8,760
broker_hostkafka-01.corp.exampleBroker/controller node written to host.name; ASCII hostname up to 253 characters

Related Generators