Apache Kafka StandardAuthorizer Denial Log
Kafka 3.9.0 KRaft StandardAuthorizer denials of topic operations by misconfigured clients retrying requests they are not allowed to make, as native kafka-authorizer.log lines with parsed ECS and kafka.* fields. About 5,100-5,200 denials a day from twelve SASL principals, around the clock with a daytime rise. Recurring episodes deny one principal four different operations on one topic within minutes.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/messaging-apache-kafka-authorizer/generator.yml \
--id kafka-authorizer \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| READ | Denied consumer Fetch, authorized by the broker | 55.4-56.5% of records per day | api |
| WRITE | Denied Produce, authorized by the broker | 38.9-40.2% of records per day | api |
| ALTER_CONFIGS | Denied AlterConfigs, forwarded to the controller | 2.4-3.0% of records per day | api |
| DELETE | Denied DeleteTopics, forwarded to the controller | 2.0-2.2% of records per day | api |
Realism Features
- One combined KRaft broker/controller, twelve SASL User principals each bound to one client address, and four existing topics. Clients hold only DESCRIBE ACLs, so every attempt ends in DefaultDeny; application accounts are denied reads and writes, and only the two operations accounts, the analyst and the audit exporter are denied administrative requests.
- The nine application service accounts produce about 4,500 denials a day (89%), an even floor around the clock plus a broad daytime rise peaking at 11:00-13:00; the analyst and operations accounts produce about 660 a day (11%), 600 of them between 08:00 and 18:00. That is about 130 denials an hour at night and 310-340 at the midday peak (UTC by default), with each day varying by up to 3%.
- Each client retries one denied request at a time: 1-8 Fetch or Produce attempts, or 1-3 administrative attempts, 24 s apart at the 10th percentile, 58 s in median and 165 s at the 90th. After a run the client tries another operation on the same topic with probability 0.3, in median about 150 s later. 93% of denials follow a denial of the same principal within 10 minutes; consecutive records are 10.6 s apart in median and 99% within 90 s.
- All 13 native fields (layout time, level and logger plus the ten audit message fields) are generated and parsed; forwarded AlterConfigs and DeleteTopics keep the original client principal and address. Only INFO denials of explicitly requested operations are in this stream; allowed decisions, filter checks, authentication and successful traffic are not. event.created and event.ingested are synthetic collector times.
- The format is implemented from the tagged Kafka 3.9.0 source and its unit-test expectation, not verified byte for byte against a running broker. Elastic publishes no authorizer sample and its Kafka authentication test log is a different stream, so the ECS mapping is this pack's own. The JVM is assumed to run in UTC; volumes, hour curves and client weights are synthetic, and tight-loop retry floods, other rules (MatchingAcl, SuperUser), other resource types and cluster-level denials are not generated.
- Episode steps come faster than ordinary operation changes: an episode moves to the next operation after about 15-85 s, while an ordinary client switching operations on one topic does so after about 150 s in median (15-17% within a minute).
Sample Output
{
"@timestamp": "2026-10-01T14:03:17.180Z",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "authorization-denied",
"category": [
"api"
],
"created": "2026-10-01T14:03:17.795Z",
"ingested": "2026-10-01T14:03:19.008Z",
"kind": "event",
"original": "[2026-10-01 14:03:17,180] INFO Principal = User:ops-config is Denied operation = ALTER_CONFIGS from host = 10.40.3.20 on resource = Topic:LITERAL:metrics-internal for request = AlterConfigs with resourceRefCount = 1 based on rule DefaultDeny (kafka.authorizer.logger)",
"outcome": "failure",
"timezone": "+00:00",
"type": [
"denied"
]
},
"host": {
"name": "kafka-01.corp.example"
},
"kafka": {
"authorization_result": "Denied",
"log": {
"class": "kafka.authorizer.logger",
"component": "unknown"
},
"operation": "ALTER_CONFIGS",
"principal": "User:ops-config",
"request": "AlterConfigs",
"resource": {
"name": "metrics-internal",
"pattern_type": "LITERAL",
"type": "Topic"
},
"resource_ref_count": 1,
"rule": "DefaultDeny"
},
"log": {
"level": "INFO",
"logger": "kafka.authorizer.logger"
},
"message": "Principal = User:ops-config is Denied operation = ALTER_CONFIGS from host = 10.40.3.20 on resource = Topic:LITERAL:metrics-internal for request = AlterConfigs with resourceRefCount = 1 based on rule DefaultDeny",
"related": {
"ip": [
"10.40.3.20"
],
"user": [
"ops-config"
]
},
"source": {
"ip": "10.40.3.20"
},
"tags": [
"preserve_original_event"
],
"user": {
"name": "ops-config"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add recurring episodes to the background; false produces only the background |
| anomaly_interval_hours | 24 | Hours between episode starts, 1 to 8,760 |
| broker_host | kafka-01.corp.example | Broker/controller node written to host.name; ASCII hostname up to 253 characters |
Related Generators
Windows Security Event Log
The Security channel of Windows Event Log — logon/logoff sessions, process creation, privilege escalation, account management, and audit policy changes from a 120-host Active Directory fleet.
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Nginx Access & Error Logs
Nginx reverse proxy and web server — access logs with upstream timing, error logs with module context, bot/crawler traffic, scanner probes, and correlated 4xx/5xx error entries.