Eltex MES Switch Syslog
Syslog messages of one Eltex MES5324 access switch as ECS JSON: HTTPS logins of administrators and automation accounts, interface speed and link changes, MAC table notifications and logging configuration changes, with the native message body verbatim in event.original and message. About 900 messages an hour around the clock, almost all of them MAC table notifications. Recurring episodes join a run of failed logins of a shared account to a port disruption and logging changes on the same switch.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-eltex-mes/generator.yml \
--id mes \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| BRG_MACNTFY-I-MAC_CHANGED (Removed) | MAC address removed by aging or after a port Down (mac_removed) | 48.79% typical share | network |
| BRG_MACNTFY-I-MAC_CHANGED (learnt) | MAC address learnt, including relearning after Up (mac_learned) | 48.77% typical share | network |
| AAA-I-CONNECT | HTTPS login accepted (login_accepted) | 0.89% typical share | authentication |
| AAA-I-DISCONNECT | HTTPS session terminated (session_terminated) | 0.89% typical share | authentication |
| LINK-W-Down | Interface link down (interface_down) | 0.19% typical share | network |
| LINK-W-Up | Interface link up (interface_up) | 0.19% typical share | network |
| LINK-N-PortConfRecover | Server port set to 1G or back to 10G (interface_speed_changed) | 0.11% typical share | configuration, network |
| AAA-W-REJECT | HTTPS login rejected (login_rejected) | 0.09% typical share | authentication |
| SYSLOG-N-CLEARLOGGINGFILE | Local logging file cleared (logging_file_cleared) | 0.04% typical share | configuration |
| SYSLOG-N-NOSYSLOGSERVER | Auxiliary syslog receiver deleted (syslog_server_deleted) | 0.02% typical share | configuration |
| SYSLOG-N-NEWSYSLOGSERVER | Auxiliary syslog receiver added (syslog_server_added) | 0.02% typical share | configuration |
Realism Features
- One switch with 24 ports: twenty access ports with 64 MAC addresses each and four dual-rate 1G/10G server ports with three each, configured for 10G. About 900 messages an hour (±5% from hour to hour) at random moments around the clock, with no daily cycle. Every endpoint, port and administrator follows its own random schedule, with no fixed period, rotation or global wave.
- Each MAC address is learnt and later removed by aging after lognormal present and absent times; a Down removes every present address of that port one by one, and the addresses are learnt again after Up. Ports flap on their own (Up after seconds to minutes), and administrators also shut ports down and re-enable them.
- Two automation accounts log in over HTTPS from their own addresses and change nothing: nms-backup about every hour, nms-poll about every ten minutes, each cycle a few percent early or late. They make up most logins and almost never fail.
- Six administrator accounts log in over HTTPS: the shared admin and noc-duty accounts, used by several NOC engineers, about every one and a half to two and a half hours each, and four personal accounts about twice a day. Mistyped passwords come mostly from the shared accounts, on every day; a single failure is the most common, each longer run up to four in a row is rarer, and consecutive failures stay below a lockout threshold of 5. About 8% of login attempts fail. An ordinary session changes something only now and then, usually a port shutdown and re-enable; changed state is restored within the session or by the next administrator to log in.
- About three days in ten carry planned work: most shared-account sessions that day are change sessions, whose login often starts with mistyped passwords after a password rotation and which set a server port to 1G, clear the logging file and remove the auxiliary receiver, usually in that order, before the changes are restored. A typical change day has about 182 logins, 26 failed logins, 37 speed changes, 15 file clears and 9 receiver removals; another day about 185, 12, 9, 1.7 and 1.1. Rates, durations and operation mix are synthetic workload choices, not measured Eltex production frequencies.
- Message bodies only: the catalog carries no firmware version, and no syslog priority, timestamp, hostname or transport framing is emitted; observer.model and the parsed eltex.mes.details fields are normalization. The learnt form comes from the catalog parameter table, so its live capitalization is unconfirmed. Console, Telnet and SSH sessions are not modeled. Configuration lines name no user, so linking them to a login is temporal only. Messages the switch writes within milliseconds appear seconds apart: a Down follows its speed change after a median of 3.0 s, and the MAC removals after an access port Down take a median of 3.3 minutes. No live capture, exact-build trace or maintained Elastic integration for Eltex MES was available for comparison.
Sample Output
{
"@timestamp": "2026-09-02T21:18:31.319+00:00",
"destination": {
"ip": "10.40.0.11"
},
"ecs": {
"version": "8.17.0"
},
"eltex": {
"mes": {
"component": "AAA",
"details": {
"connection": {
"auth_method": "local user table",
"type": "https"
}
},
"mnemonic": "REJECT",
"severity_code": "W"
}
},
"event": {
"action": "login_rejected",
"category": [
"authentication"
],
"dataset": "eltex.mes.syslog",
"kind": "event",
"module": "eltex",
"original": "AAA-W-REJECT: New https connection for user noc-duty, source 10.40.1.12 destination 10.40.0.11, local user table REJECTED.",
"outcome": "failure",
"type": [
"start",
"denied"
]
},
"log": {
"level": "warning"
},
"message": "AAA-W-REJECT: New https connection for user noc-duty, source 10.40.1.12 destination 10.40.0.11, local user table REJECTED.",
"observer": {
"hostname": "mes-access-01",
"ip": [
"10.40.0.11"
],
"model": "MES5324",
"name": "mes-access-01",
"product": "MES",
"type": "switch",
"vendor": "Eltex"
},
"source": {
"ip": "10.40.1.12"
},
"user": {
"name": "noc-duty"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| switch_name | mes-access-01 | Switch name in observer.name and observer.hostname |
| switch_ip | 10.40.0.11 | Switch address; destination of administrator logins |
| syslog_server_ip | 10.40.0.12 | Auxiliary syslog receiver removed and re-added; the collector receiving this stream is a second destination that is never changed |
| anomaly_mode | true | Include periodic anomaly episodes; false gives background only |
| anomaly_interval_hours | 24 | Hours between episode starts; 6 to 8760, smaller values fail validation |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.