Kerio Control Filter Log
URL content-rule records that one Kerio Control firewall writes to its Filter log, as ECS JSON with the Filter log line in the GFI-documented layout in event.original, for one office user segment. About 5,000 records a day: 32 users browse on a working-day curve and hit deny rules for social networks, anonymizers and file sharing and an allow rule on executable downloads, while their computers fetch updates round the clock. Recurring episodes show one user blocked on two different anonymizers, then downloading a tunneling or remote-access client within an hour.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-kerio-control/generator.yml \
--id kerio-control \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| DENY URL (Deny social networks) | GET to a social network denied | 38.19% of records | web |
| ALLOW URL (Allow automatic updates and MS Windows activation) | GET to an update or activation host allowed | 27.59% of records | web |
| DENY URL (Deny anonymizers) | GET to a web proxy denied | 14.29% of records | web |
| ALLOW URL (Log executable downloads) | Installer GET allowed and logged | 9.32% of records | web |
| DENY URL (Deny file sharing, GET) | GET to a file-sharing site denied | 8.01% of records | web |
| DENY URL (Deny file sharing, POST) | Upload POST to a file-sharing site denied | 2.60% of records | web |
Realism Features
- Thirty-two users, one client address each, browse on a working-day curve in UTC: 0.093 records/s from 08:00 to 17:00, 0.033 in 07:00-08:00 and 17:00-20:00, 0.003 at night. The computers fetch updates and activation checks round the clock at 0.016 records/s, attributed to the user of the computer. About 5,000 records a day, varying by about 3% from day to day; consecutive records are a median 6 s apart in office hours, 14 s in the shoulder hours and about 40 s at night. Every day has the same curve, with no weekend dip.
- Each user has a fixed log-normal propensity, bounded to a factor of about 5 between the quietest and the busiest user, so some users hit blocked sites far more often than others, yet every user appears every day. The busiest quarter of the users (jsmith, mbrown, akowalski, dlee, epetrova, fgarcia, hmuller and ikhan by default) take remote-access and tunnel clients regularly, the others rarely.
- Browsing comes in bursts: social networks (43% of browsing actions, 1-6 denials, median gap 25 s, host kept or switched), anonymizers (22%, 1-4 denials, median gap 45 s, often on different proxies), file sharing (18%, 1-3 denials, 25% of them upload POSTs) and executable downloads (17%, 1-2 installers, from a tunnel-client host in 45% of the busiest users' downloads and 5% of the others'). After 22% of anonymizer bursts the user downloads an installer about five minutes later, from a tunnel-client host in 65% of cases for the busiest users and 25% for the others. Updates come as 1-4 allowed requests to one host.
- Over four days the background holds about 1,800-2,100 pairs of denials on two different anonymizers by one user within an hour, 160-225 tunnel-client downloads and 95-130 tunnel-client downloads within an hour of an anonymizer denial; each of the busiest users downloads about 9-35 tunnel clients in four days, each other user 0-8. Every user, anonymizer host, tunnel-client host and rule used by the chain occurs in background, and no field labels an episode.
- event.original follows the URL-rule line that GFI documents with one raw ALLOW example; DENY lines use the same layout. The raw line has second resolution, the firewall clock is UTC and no syslog framing is produced. No Elastic integration exists, so the ECS mapping is an assumption; kerio_control.filter keeps the rule type and action token.
- Only HTTP URL lines are generated: HTTPS, FTP rules, the Drop action and hosts with no logged-in user are not documented in enough detail. Packet-rule records of the Filter log and the other Kerio Control logs (Http, Web, Security, Connection) are out of scope.
- Rule names and the set of logged rules are an assumed office configuration (the automatic-updates rule is the one GFI names); rates, host lists and user behavior are training assumptions, not measured production volume. Requests of one burst are at least a few seconds apart, and at night about a minute apart, rather than the sub-second spacing of a page load.
Sample Output
{
"@timestamp": "2026-09-01T18:55:36+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "ALLOW",
"category": [
"web",
"network"
],
"dataset": "kerio_control.filter",
"kind": "event",
"original": "[01/Sep/2026 18:55:36] ALLOW URL \u0027Log executable downloads\u0027 10.10.20.12 mbrown HTTP GET http://download.socksclient.example/socksclient/10.3/socksclient-setup.exe",
"type": [
"access",
"allowed"
]
},
"http": {
"request": {
"method": "GET"
}
},
"kerio_control": {
"filter": {
"action": "ALLOW",
"rule_type": "URL"
}
},
"observer": {
"hostname": "kerio-fw-01.example.test",
"product": "Kerio Control",
"type": "firewall",
"vendor": "GFI"
},
"related": {
"hosts": [
"download.socksclient.example"
],
"ip": [
"10.10.20.12"
],
"user": [
"mbrown"
]
},
"rule": {
"name": "Log executable downloads"
},
"source": {
"ip": "10.10.20.12"
},
"url": {
"domain": "download.socksclient.example",
"full": "http://download.socksclient.example/socksclient/10.3/socksclient-setup.exe",
"path": "/socksclient/10.3/socksclient-setup.exe",
"scheme": "http"
},
"user": {
"name": "mbrown"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add periodic episodes to the background |
| anomaly_interval_hours | 24 | Episode interval in source hours, 2-8760 |
| firewall_host | kerio-fw-01.example.test | Firewall name in observer.hostname |
| client_prefix | 10.10.20. | Client addresses are this prefix plus a host number |
| client_first | 11 | First client host number |
| user_count | 32 | Number of users, one address each, taken in order from samples/users.csv; the first quarter (at least two) are the busiest (4-40; client_first + user_count at most 255) |
| anonymizer_hosts | [webproxy.hideme.example, free.unblocker.example, surf.anonymous.example, go.bypassgate.example] | Hosts denied by Deny anonymizers (at least 3) |
| tunnel_hosts | [dl.remotedesk.example, get.tunnelvpn.example, download.socksclient.example] | Tunnel and remote-access client download hosts (at least 2) |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.