Hub
Network

Eltex ESR Router Syslog

Eltex ESR-series (software 1.40) remote syslog records of one router as ECS JSON: SSH administration, local account and configuration changes, firewall, NAT and IPS logs. event.original holds the RFC 5424 frame and message the documented %GROUP-SEVERITY-MNEMONIC body. Weekly episodes by default join three failed passwords to a new privileged account and its first login.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-eltex-esr/generator.yml \
  --id esr \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
firewall_permitted%FIREWALL-I-LOG permit, rules 10/20/3059.09% measured sharenetwork
firewall_denied%FIREWALL-I-LOG deny, rule 4019.21% measured sharenetwork
snat_translation%NAT-I-LOG source translation14.29% measured sharenetwork
ips_drop%IPS-I-INFO drop1.45% measured shareintrusion_detection
ssh_password_accepted%AAA-I-SSH password accepted1.31% measured shareauthentication
session_opened%AAA-LOCAL-I-SESSION session opened1.31% measured shareauthentication
session_closed%AAA-LOCAL-I-SESSION session closed1.31% measured shareauthentication
configuration_applied%SYS-W-EVENT configuration applied0.54% measured shareconfiguration
system_time_changed%TIME-I-INFO system clock set0.32% measured shareconfiguration
user_privilege_changed%USER-I-INFO account privilege changed0.29% measured shareiam
enable_password_changed%USER-I-INFO privilege 15 enable password changed0.29% measured shareiam, configuration
user_created%USER-I-ADD temporary account created0.23% measured shareiam
user_removed%USER-I-ADD temporary account removed0.23% measured shareiam
ssh_password_failed%AAA-I-SSH password failed0.07% measured shareauthentication
user_password_changed%USER-I-INFO account password changed0.06% measured shareiam

Realism Features

  • About 8,900 records a day by hour, UTC by default: 609 an hour in 06:00-16:00, 336 in 16:00-20:00 and 147 at night, varying by up to 10% a day. SSH and maintenance records are part of this volume and firewall, NAT and IPS records make up the rest. Sequence numbers grow by one, or by 2-7 in 15% of records for device messages outside this subset.
  • Each administrator starts about 16 sessions a day on the hourly curve with a shared daily workload factor. A connection has 0-3 failed passwords on one TCP source port before success (92 / 5.5 / 1.5 / 1%); 1.5% give up after 1-3 failures and 70% of those retry from a new port. Failures stay below the five-attempt lockout threshold, assuming the counter resets after 300 seconds without failures.
  • A session holds 0-6 maintenance operations: create or remove a temporary account, change a privilege, a password or the enable password, set the clock. Half of the administrator sessions, when an account is absent, run an onboarding routine instead: rotate the enable password, create an account, raise it from 1 to 14, apply, set the clock, then test the new account's login. Changes are applied before logout, and changes pending in another session are not visible.
  • The backup and monitoring account logs in about 48 times a day around the clock with a stored password that does not fail, for about 15 seconds without changes. Temporary accounts get a planned lifetime (median 40 minutes) and are removed by the next session after it passes; they log in only after their creation is applied and never after removal, about eight times a day from either administrator address. Failed passwords are about 5.5% of SSH password records.
  • Permit, deny, SNAT and IPS drop records over a fixed IPv4 flow inventory with fresh ephemeral source and NAT ports; rules 10/20/30 permit and rule 40 denies throughout. All gaps are log-normal, with no fixed periods, rotations or per-actor cooldowns.
  • Administration is far busier than on a production router: temporary accounts are created and removed many times a day and the enable password changes several times a day. Steps of one session are seconds apart (password accepted to session opened a median 6 s in office hours, about 20 s at night), where a router logs them within a second.
  • USER messages carry only the target account, so linking configuration changes to the administrator relies on the surrounding session. The time-change body has no clock values, and CLI commit/confirm records are omitted on the assumption that every commit is confirmed.
  • The ssh session slot substitutes the documented console value, as no SSH capture from a real device was available. Non-AAA app names and facility local0 are assumptions. IPv6, Telnet/console, public-key and remote AAA logins, lockout records, rollback and full traffic session lifecycles are outside the subset. Rates are training assumptions, and no Elastic integration exists for ESR, so the ECS mapping is inferred.

Sample Output

{
  "@timestamp": "2026-09-01T21:52:43+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "user_privilege_changed",
    "category": [
      "iam"
    ],
    "dataset": "eltex.esr.syslog",
    "kind": "event",
    "module": "eltex",
    "original": "\u003c134\u003e1 2026-09-01T21:52:43+00:00 esr-edge-01 user - - - 15506: %USER-I-INFO: Privilege level of user svc_remote_001 was changed from 1 to 14",
    "outcome": "success",
    "type": [
      "change"
    ]
  },
  "message": "%USER-I-INFO: Privilege level of user svc_remote_001 was changed from 1 to 14",
  "log": {
    "level": "info",
    "syslog": {
      "priority": 134,
      "facility": {
        "code": 16
      },
      "severity": {
        "code": 6
      },
      "appname": "user",
      "version": "1"
    }
  },
  "observer": {
    "hostname": "esr-edge-01",
    "ip": [
      "10.50.0.1"
    ],
    "name": "esr-edge-01",
    "product": "ESR",
    "type": "router",
    "vendor": "Eltex"
  },
  "eltex": {
    "esr": {
      "group": "USER",
      "mnemonic": "INFO",
      "severity_code": "I",
      "sequence_number": 15506,
      "details": {
        "privilege": {
          "new": 14,
          "old": 1
        }
      }
    }
  },
  "user": {
    "target": {
      "name": "svc_remote_001"
    }
  },
  "related": {
    "user": [
      "svc_remote_001"
    ]
  }
}

Parameters

ParameterDefaultDescription
router_nameesr-edge-01Router hostname in the syslog frame and observer.*
router_ip10.50.0.1Management address (destination.ip of SSH records)
normal_usernetopsFirst privilege 15 administrator
normal_source_ip10.50.1.25First administrator's client address
unusual_useradminSecond privilege 15 administrator
unusual_source_ip10.99.4.33Second administrator's client address
automation_usernetbackupBackup and monitoring account
automation_source_ip10.50.1.60Backup and monitoring server address
service_user_prefixsvc_remote_Temporary accounts are this prefix plus 001-005
anomaly_modetrueAdd periodic episodes to the background
anomaly_interval_hours168Episode interval in source hours, 6 to 8,760

Related Generators