Hub
Network

Kaspersky NGFW Firewall Session Log

Kaspersky NGFW 1.0 Firewall session log (CEF) of one device as ECS JSON, with paired Session start and Firewall records for clients of a user segment reaching the internet, two internal file servers and an internal DNS server. About 14,000 records a day on a UTC office-hours curve. Recurring episodes show one client reading two large files from one server over SMB, then uploading more than 50 MB to a cloud destination.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-kaspersky-ngfw/generator.yml \
  --id ngfw \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
Session start (HTTPS)HTTPS session (TCP/443) created21.69% sharenetwork
Firewall (HTTPS)HTTPS session (TCP/443) removed, with counters21.69% sharenetwork
Session start (DNS)DNS session (UDP/53) created15.81% sharenetwork
Firewall (DNS)DNS session (UDP/53) removed, with counters15.81% sharenetwork
Session start (SMB)SMB session (TCP/445) created10.69% sharenetwork
Firewall (SMB)SMB session (TCP/445) removed, with counters10.69% sharenetwork
Session start (HTTP)HTTP session (TCP/80) created1.82% sharenetwork
Firewall (HTTP)HTTP session (TCP/80) removed, with counters1.82% sharenetwork

Realism Features

  • About 14,000 records a day (±3% from day to day) on a UTC hour-of-day curve: about 960 records an hour 06:00-16:00, 530 at 16:00-20:00 and 230 at night. The activity mix is the same at every hour and half of the records are session starts. Rates, sizes and throughputs are training assumptions, not measured production volume: this is a sampled view of a small office.
  • Each new activity picks a client by a fixed random per-client weight, so clients act independently. Web (62%) is HTTPS to 40 internet addresses with skewed popularity, in 60% of cases after a DNS query; cloud (8%) is HTTPS to the cloud-storage addresses, 18% of it uploads (median 35 MB); plain HTTP and DNS-only take 6% each.
  • SMB (18%) comes in bursts of 1-7 transfers from one file server with a per-burst size scale (median 300 kB), so several reads above 50 MB can follow within minutes. After any read above 50 MB the same client uploads to the cloud with probability 0.25, about 10 minutes later.
  • Durations follow the transferred volume and a log-normal throughput (LAN median 20 MB/s, internet 2 MB/s), with directional packet and byte counters. A session start and end share devicePayloadId, addresses, ports and start time; session IDs grow by a random 1-40. UDP sessions end after an assumed 30 s idle timeout plus a random sweep delay. Records a real device logs milliseconds apart are seconds apart: a DNS query and the connection it resolves start a median 5 s apart (90% within 20 s), and session ends come a few seconds after the last packet, so cn1 includes that delay (DNS sessions: median 45 s instead of about 34 s).
  • No field labels an episode. Large SMB read bursts, large cloud uploads and uploads after one large read occur in background in both modes; an ordinary upload that would complete the chain (two reads above 50 MB from one server by the same client, the first at most one hour earlier) is 5-45 MB, while an upload more than an hour after the first read is left as is. Episode reads come from the upper tail of the background SMB size distribution, and the episode client is picked by the same per-client weights. Each episode adds its own records, so counts of large SMB reads and large uploads are about two and one per episode higher than with anomaly_mode off.
  • Kaspersky publishes the CEF header, the Firewall event names and the key table but no complete raw Firewall message, so key order after rt dtz, the label literals and optional-field omission are assumptions. app and sproc are always Unknown; reason, decryption, profile, application name and DNS domain fields are omitted.
  • All sessions match a rule with the documented Inspect action (FullMatch=yes); denied traffic, ICMP, NAT and the other NGFW logs are out of scope, and the device time zone is UTC. No Elastic integration exists for this source, so the ECS mapping, including network.protocol inferred from the port, is an assumption.

Sample Output

{
  "@timestamp": "2026-09-01T06:12:30+00:00",
  "destination": {
    "bytes": 1616836,
    "ip": "203.0.113.13",
    "packets": 31093,
    "port": 443
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "Firewall",
    "category": [
      "network"
    ],
    "dataset": "kaspersky.ngfw",
    "duration": 130000000000,
    "end": "2026-09-01T06:12:30+00:00",
    "kind": "event",
    "original": "CEF:0|Kaspersky|NGFW|1.0.0.0|Firewall|Firewall|Unknown|rt=2026-09-01T06:12:30Z dtz=UTC+00:00 cs4=Low cs4Label=Priority devicePayloadId=2537811 cs1=Users to Internet cs1Label=SecurityRule act=Inspect FullMatch=yes start=2026-09-01T06:10:20Z end=2026-09-01T06:12:30Z cn1=130 cn1Label=Duration cn2=53191 cn2Label=ClientPackets cn3=31093 cn3Label=ServerPackets in=61463722 out=1616836 dvchost=ngfw-01.example.test src=10.20.1.33 dst=203.0.113.13 proto=TCP spt=57094 dpt=443 KasperskyNGFWTCPRedir=no app=Unknown sproc=Unknown",
    "start": "2026-09-01T06:10:20+00:00",
    "type": [
      "connection",
      "end"
    ]
  },
  "kaspersky": {
    "ngfw": {
      "action": "Inspect",
      "full_match": "yes",
      "session_id": "2537811"
    }
  },
  "network": {
    "bytes": 63080558,
    "packets": 84284,
    "protocol": "tls",
    "transport": "tcp"
  },
  "observer": {
    "hostname": "ngfw-01.example.test",
    "product": "NGFW",
    "vendor": "Kaspersky",
    "version": "1.0.0.0"
  },
  "related": {
    "ip": [
      "10.20.1.33",
      "203.0.113.13"
    ]
  },
  "rule": {
    "name": "Users to Internet"
  },
  "source": {
    "bytes": 61463722,
    "ip": "10.20.1.33",
    "packets": 53191,
    "port": 57094
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd periodic episodes to the background
anomaly_interval_hours24Episode interval in source hours, 2 to 8,760
device_hostngfw-01.example.testWritten to dvchost and observer.hostname
device_version1.0.0.0CEF header version (1.0.0.x)
client_prefix10.20.1.Client addresses are this prefix plus a host number
client_first21First client host number
client_count24Number of clients, at least 4; client_first + client_count at most 255
file_servers10.20.2.14, 10.20.2.15SMB servers
dns_server10.20.0.53DNS resolver
cloud_destinations203.0.113.10, 203.0.113.11, 203.0.113.12, 203.0.113.13Cloud-storage addresses, at least 2

Related Generators