Progress Kemp LoadMaster ESP CEF
Edge Security Pack (ESP) user logs of a Progress Kemp LoadMaster in Common Event Format, for one virtual service that pre-authenticates a webmail portal, as ECS JSON with the CEF body in event.original and the parsed header and extension under kemp.loadmaster. About 40,000 records a day from 400 portal users follow a working-day curve in UTC. Recurring episodes show repeated ESP logon failures followed by a logon and an Exchange control panel request. The rates are a synthetic workload, not measured LoadMaster traffic.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-kemp-loadmaster/generator.yml \
--id kemp-loadmaster \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| Request (14) | Authenticated portal request | 51.7% of records | web |
| SSL accept (2) | TLS connection accepted by the virtual service | 12.0% of records | network |
| Connected (4) | Connection to a real server | 11.4% of records | network |
| Attempt (15) | Unauthenticated request | 5.6% of records | web |
| User AAA (100) | Successful authentication against the AAA server | 5.2% of records | authentication |
| Logged on (8) | ESP logon | 5.2% of records | authentication, session |
| Logged off (6) | ESP logoff | 2.9% of records | authentication, session |
| User session kill (102) | Session removed after logoff | 2.9% of records | session |
| User session timeout (101) | Session ended after the idle time | 2.3% of records | session |
| Access Denied (9) | Failed ESP logon | 0.4% of records | authentication |
| Connection timed out (3) | Client connection timed out | 0.2% of records | network |
| Connection failed (5) | Real server connection failed | 0.2% of records | network |
Realism Features
- The virtual service logs about 40,000 records a day (+/- 3% from day to day) on a working-day curve in UTC: about 0.2 records per second from 21:00 to 03:00, rising from about 03:00 to a peak of about 0.87 per second between 10:00 and 12:00, and declining through the afternoon and evening. Office hours are fixed to UTC and there is no weekly cycle: weekends look like weekdays.
- The portal has 400 users, each with a fixed activity level: the most active open about four times as many sessions as the least active, and a user averages about five sessions a day. About 40 distinct users are active in a night hour and about 170 in the 11:00 hour. A user connects from their office address or, in 30% of sessions, from a random external address; anonymous clients add about 240 TLS accepts a day around the clock that time out or send one Attempt.
- A session is a TLS accept and an unauthenticated Attempt for /owa/, then User AAA, Logged on and Connected to a real server. About 4% of logons follow one or more Access Denied records (under 1% of sessions have three or more), and 15% of sessions with a denial end without a logon, so about 6% of logon attempts fail. Requests follow with log-normal gaps, about 5% under /ecp/; new client connections add SSL accept and Connected, rarely after a Connection failed. A session ends with Logged off plus User session kill, or with User session timeout after the idle time.
- Names, severities, extension keys and key order follow the vendor examples for each class ID, including Device Version 1.0 (the CEF header table states 0). No raw syslog line is documented for the L7 ESP classes, so event.original holds the CEF body only. CEF logging requires firmware 7.2.50 or later; session records 101 and 102 follow the 7.2.53 behavior.
- User AAA failure strings are not documented, so User AAA appears only for successful logons and a failed logon produces Access Denied alone. Access Blocked, Access Locked, Access Disabled, Password Expired, User interaction, WAF, SMTP, Kill all sessions and Flush SSO cache are not modelled. The User Logs page also says a session is deleted on invalid credentials; the pack emits no 101/102 session records after denials.
- Ordinary traffic contains every chain fragment: logons that follow three or more denials from the same address within 30 minutes (about 40 to 70 per four days) and /ecp/ requests by almost every user. When three denials and then a logon from one address precede a request of that user from that address, and the first of those denials is at most 30 minutes old, the request is for an /owa/ path, with the method that path always uses (POST for /owa/service.svc and /owa/ev.owa2, GET otherwise). With anomaly_mode true the count of logons after three or more denials is about one per episode higher; the total volume is the same in both modes. The chain shows portal behavior; it does not show whether the account was compromised.
- Records that a LoadMaster writes in the same instant (User AAA and Logged on, Logged off and User session kill, SSL accept and Attempt) are seconds apart: 2 s at the median, 7 s at the 90th percentile, up to about a minute at night. Timestamps have one-second resolution.
- The episode start window is narrower than the night: after a first episode in the evening, later ones can stay in the evening for several days.
Sample Output
{
"@timestamp": "2026-09-01T18:34:30+00:00",
"destination": {
"ip": "10.42.20.15",
"port": 443
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "request",
"category": [
"web"
],
"code": "14",
"dataset": "kemp_loadmaster.esp",
"kind": "event",
"module": "kemp_loadmaster",
"original": "CEF:0|Kemp|LM|1.0|14|Request|1|vs=10.42.20.15:443 event=Request srcip=10.60.26.201 srcport=53479 method=GET url=https://mail.example.test/ecp/ user=d.kaur@example.test useragent=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Edg/128.0.0.0",
"severity": 1,
"type": [
"access"
]
},
"http": {
"request": {
"method": "GET"
}
},
"kemp": {
"loadmaster": {
"cef": {
"device_event_class_id": "14",
"device_product": "LM",
"device_vendor": "Kemp",
"device_version": "1.0",
"name": "Request",
"severity": 1,
"version": 0
},
"extension": {
"event": "Request",
"method": "GET",
"srcip": "10.60.26.201",
"srcport": "53479",
"url": "https://mail.example.test/ecp/",
"user": "d.kaur@example.test",
"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Edg/128.0.0.0",
"vs": "10.42.20.15:443"
}
}
},
"observer": {
"hostname": "lm-edge-01",
"product": "LoadMaster",
"type": "load-balancer",
"vendor": "Progress Kemp"
},
"related": {
"ip": [
"10.60.26.201",
"10.42.20.15"
],
"user": [
"d.kaur@example.test"
]
},
"source": {
"ip": "10.60.26.201",
"port": 53479
},
"url": {
"domain": "mail.example.test",
"full": "https://mail.example.test/ecp/",
"path": "/ecp/",
"scheme": "https"
},
"user": {
"name": "d.kaur@example.test"
},
"user_agent": {
"original": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Edg/128.0.0.0"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| device_name | lm-edge-01 | LoadMaster host name in observer.hostname |
| virtual_ip | 10.42.20.15 | ESP virtual service address (vs, destination.ip) |
| virtual_port | 443 | Virtual service port |
| portal_host | mail.example.test | Host in request URLs |
| real_servers | [172.20.0.21, 172.20.0.22, 172.20.0.23] | Real servers in Connected and Connection failed |
| real_server_port | 443 | Real server port |
| user_domain | example.test | domain of User AAA |
| sso_domain | EXAMPLE-ESP | ESP SSO domain in session timeout and kill records |
| aaa_server | 10.42.30.10 | Authentication server in User AAA |
| aaa_protocol | LDAP Unencrypted | Authentication protocol in User AAA |
| session_idle_seconds | 900 | Idle time before User session timeout |
| probes_per_day | 240 | Anonymous client connections per day |
| anomaly_mode | true | Include anomaly episodes; false emits ordinary traffic only |
| anomaly_interval_hours | 24 | Hours between episodes, from the actual start of the previous one (6 to 8760) |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.