Eltex ESR Router Syslog
Eltex ESR-series (software 1.40) remote syslog records of one router as ECS JSON: SSH administration, local account and configuration changes, firewall, NAT and IPS logs. event.original holds the RFC 5424 frame and message the documented %GROUP-SEVERITY-MNEMONIC body. Weekly episodes by default join three failed passwords to a new privileged account and its first login.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-eltex-esr/generator.yml \
--id esr \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| firewall_permitted | %FIREWALL-I-LOG permit, rules 10/20/30 | 59.09% measured share | network |
| firewall_denied | %FIREWALL-I-LOG deny, rule 40 | 19.21% measured share | network |
| snat_translation | %NAT-I-LOG source translation | 14.29% measured share | network |
| ips_drop | %IPS-I-INFO drop | 1.45% measured share | intrusion_detection |
| ssh_password_accepted | %AAA-I-SSH password accepted | 1.31% measured share | authentication |
| session_opened | %AAA-LOCAL-I-SESSION session opened | 1.31% measured share | authentication |
| session_closed | %AAA-LOCAL-I-SESSION session closed | 1.31% measured share | authentication |
| configuration_applied | %SYS-W-EVENT configuration applied | 0.54% measured share | configuration |
| system_time_changed | %TIME-I-INFO system clock set | 0.32% measured share | configuration |
| user_privilege_changed | %USER-I-INFO account privilege changed | 0.29% measured share | iam |
| enable_password_changed | %USER-I-INFO privilege 15 enable password changed | 0.29% measured share | iam, configuration |
| user_created | %USER-I-ADD temporary account created | 0.23% measured share | iam |
| user_removed | %USER-I-ADD temporary account removed | 0.23% measured share | iam |
| ssh_password_failed | %AAA-I-SSH password failed | 0.07% measured share | authentication |
| user_password_changed | %USER-I-INFO account password changed | 0.06% measured share | iam |
Realism Features
- About 8,900 records a day by hour, UTC by default: 609 an hour in 06:00-16:00, 336 in 16:00-20:00 and 147 at night, varying by up to 10% a day. SSH and maintenance records are part of this volume and firewall, NAT and IPS records make up the rest. Sequence numbers grow by one, or by 2-7 in 15% of records for device messages outside this subset.
- Each administrator starts about 16 sessions a day on the hourly curve with a shared daily workload factor. A connection has 0-3 failed passwords on one TCP source port before success (92 / 5.5 / 1.5 / 1%); 1.5% give up after 1-3 failures and 70% of those retry from a new port. Failures stay below the five-attempt lockout threshold, assuming the counter resets after 300 seconds without failures.
- A session holds 0-6 maintenance operations: create or remove a temporary account, change a privilege, a password or the enable password, set the clock. Half of the administrator sessions, when an account is absent, run an onboarding routine instead: rotate the enable password, create an account, raise it from 1 to 14, apply, set the clock, then test the new account's login. Changes are applied before logout, and changes pending in another session are not visible.
- The backup and monitoring account logs in about 48 times a day around the clock with a stored password that does not fail, for about 15 seconds without changes. Temporary accounts get a planned lifetime (median 40 minutes) and are removed by the next session after it passes; they log in only after their creation is applied and never after removal, about eight times a day from either administrator address. Failed passwords are about 5.5% of SSH password records.
- Permit, deny, SNAT and IPS drop records over a fixed IPv4 flow inventory with fresh ephemeral source and NAT ports; rules 10/20/30 permit and rule 40 denies throughout. All gaps are log-normal, with no fixed periods, rotations or per-actor cooldowns.
- Administration is far busier than on a production router: temporary accounts are created and removed many times a day and the enable password changes several times a day. Steps of one session are seconds apart (password accepted to session opened a median 6 s in office hours, about 20 s at night), where a router logs them within a second.
- USER messages carry only the target account, so linking configuration changes to the administrator relies on the surrounding session. The time-change body has no clock values, and CLI commit/confirm records are omitted on the assumption that every commit is confirmed.
- The ssh session slot substitutes the documented console value, as no SSH capture from a real device was available. Non-AAA app names and facility local0 are assumptions. IPv6, Telnet/console, public-key and remote AAA logins, lockout records, rollback and full traffic session lifecycles are outside the subset. Rates are training assumptions, and no Elastic integration exists for ESR, so the ECS mapping is inferred.
Sample Output
{
"@timestamp": "2026-09-01T21:52:43+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "user_privilege_changed",
"category": [
"iam"
],
"dataset": "eltex.esr.syslog",
"kind": "event",
"module": "eltex",
"original": "\u003c134\u003e1 2026-09-01T21:52:43+00:00 esr-edge-01 user - - - 15506: %USER-I-INFO: Privilege level of user svc_remote_001 was changed from 1 to 14",
"outcome": "success",
"type": [
"change"
]
},
"message": "%USER-I-INFO: Privilege level of user svc_remote_001 was changed from 1 to 14",
"log": {
"level": "info",
"syslog": {
"priority": 134,
"facility": {
"code": 16
},
"severity": {
"code": 6
},
"appname": "user",
"version": "1"
}
},
"observer": {
"hostname": "esr-edge-01",
"ip": [
"10.50.0.1"
],
"name": "esr-edge-01",
"product": "ESR",
"type": "router",
"vendor": "Eltex"
},
"eltex": {
"esr": {
"group": "USER",
"mnemonic": "INFO",
"severity_code": "I",
"sequence_number": 15506,
"details": {
"privilege": {
"new": 14,
"old": 1
}
}
}
},
"user": {
"target": {
"name": "svc_remote_001"
}
},
"related": {
"user": [
"svc_remote_001"
]
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| router_name | esr-edge-01 | Router hostname in the syslog frame and observer.* |
| router_ip | 10.50.0.1 | Management address (destination.ip of SSH records) |
| normal_user | netops | First privilege 15 administrator |
| normal_source_ip | 10.50.1.25 | First administrator's client address |
| unusual_user | admin | Second privilege 15 administrator |
| unusual_source_ip | 10.99.4.33 | Second administrator's client address |
| automation_user | netbackup | Backup and monitoring account |
| automation_source_ip | 10.50.1.60 | Backup and monitoring server address |
| service_user_prefix | svc_remote_ | Temporary accounts are this prefix plus 001-005 |
| anomaly_mode | true | Add periodic episodes to the background |
| anomaly_interval_hours | 168 | Episode interval in source hours, 6 to 8,760 |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.