Hub
Network

Kerio Control Filter Log

URL content-rule records that one Kerio Control firewall writes to its Filter log, as ECS JSON with the Filter log line in the GFI-documented layout in event.original, for one office user segment. About 5,000 records a day: 32 users browse on a working-day curve and hit deny rules for social networks, anonymizers and file sharing and an allow rule on executable downloads, while their computers fetch updates round the clock. Recurring episodes show one user blocked on two different anonymizers, then downloading a tunneling or remote-access client within an hour.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-kerio-control/generator.yml \
  --id kerio-control \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
DENY URL (Deny social networks)GET to a social network denied38.19% of recordsweb
ALLOW URL (Allow automatic updates and MS Windows activation)GET to an update or activation host allowed27.59% of recordsweb
DENY URL (Deny anonymizers)GET to a web proxy denied14.29% of recordsweb
ALLOW URL (Log executable downloads)Installer GET allowed and logged9.32% of recordsweb
DENY URL (Deny file sharing, GET)GET to a file-sharing site denied8.01% of recordsweb
DENY URL (Deny file sharing, POST)Upload POST to a file-sharing site denied2.60% of recordsweb

Realism Features

  • Thirty-two users, one client address each, browse on a working-day curve in UTC: 0.093 records/s from 08:00 to 17:00, 0.033 in 07:00-08:00 and 17:00-20:00, 0.003 at night. The computers fetch updates and activation checks round the clock at 0.016 records/s, attributed to the user of the computer. About 5,000 records a day, varying by about 3% from day to day; consecutive records are a median 6 s apart in office hours, 14 s in the shoulder hours and about 40 s at night. Every day has the same curve, with no weekend dip.
  • Each user has a fixed log-normal propensity, bounded to a factor of about 5 between the quietest and the busiest user, so some users hit blocked sites far more often than others, yet every user appears every day. The busiest quarter of the users (jsmith, mbrown, akowalski, dlee, epetrova, fgarcia, hmuller and ikhan by default) take remote-access and tunnel clients regularly, the others rarely.
  • Browsing comes in bursts: social networks (43% of browsing actions, 1-6 denials, median gap 25 s, host kept or switched), anonymizers (22%, 1-4 denials, median gap 45 s, often on different proxies), file sharing (18%, 1-3 denials, 25% of them upload POSTs) and executable downloads (17%, 1-2 installers, from a tunnel-client host in 45% of the busiest users' downloads and 5% of the others'). After 22% of anonymizer bursts the user downloads an installer about five minutes later, from a tunnel-client host in 65% of cases for the busiest users and 25% for the others. Updates come as 1-4 allowed requests to one host.
  • Over four days the background holds about 1,800-2,100 pairs of denials on two different anonymizers by one user within an hour, 160-225 tunnel-client downloads and 95-130 tunnel-client downloads within an hour of an anonymizer denial; each of the busiest users downloads about 9-35 tunnel clients in four days, each other user 0-8. Every user, anonymizer host, tunnel-client host and rule used by the chain occurs in background, and no field labels an episode.
  • event.original follows the URL-rule line that GFI documents with one raw ALLOW example; DENY lines use the same layout. The raw line has second resolution, the firewall clock is UTC and no syslog framing is produced. No Elastic integration exists, so the ECS mapping is an assumption; kerio_control.filter keeps the rule type and action token.
  • Only HTTP URL lines are generated: HTTPS, FTP rules, the Drop action and hosts with no logged-in user are not documented in enough detail. Packet-rule records of the Filter log and the other Kerio Control logs (Http, Web, Security, Connection) are out of scope.
  • Rule names and the set of logged rules are an assumed office configuration (the automatic-updates rule is the one GFI names); rates, host lists and user behavior are training assumptions, not measured production volume. Requests of one burst are at least a few seconds apart, and at night about a minute apart, rather than the sub-second spacing of a page load.

Sample Output

{
  "@timestamp": "2026-09-01T18:55:36+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "ALLOW",
    "category": [
      "web",
      "network"
    ],
    "dataset": "kerio_control.filter",
    "kind": "event",
    "original": "[01/Sep/2026 18:55:36] ALLOW URL \u0027Log executable downloads\u0027 10.10.20.12 mbrown HTTP GET http://download.socksclient.example/socksclient/10.3/socksclient-setup.exe",
    "type": [
      "access",
      "allowed"
    ]
  },
  "http": {
    "request": {
      "method": "GET"
    }
  },
  "kerio_control": {
    "filter": {
      "action": "ALLOW",
      "rule_type": "URL"
    }
  },
  "observer": {
    "hostname": "kerio-fw-01.example.test",
    "product": "Kerio Control",
    "type": "firewall",
    "vendor": "GFI"
  },
  "related": {
    "hosts": [
      "download.socksclient.example"
    ],
    "ip": [
      "10.10.20.12"
    ],
    "user": [
      "mbrown"
    ]
  },
  "rule": {
    "name": "Log executable downloads"
  },
  "source": {
    "ip": "10.10.20.12"
  },
  "url": {
    "domain": "download.socksclient.example",
    "full": "http://download.socksclient.example/socksclient/10.3/socksclient-setup.exe",
    "path": "/socksclient/10.3/socksclient-setup.exe",
    "scheme": "http"
  },
  "user": {
    "name": "mbrown"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd periodic episodes to the background
anomaly_interval_hours24Episode interval in source hours, 2-8760
firewall_hostkerio-fw-01.example.testFirewall name in observer.hostname
client_prefix10.10.20.Client addresses are this prefix plus a host number
client_first11First client host number
user_count32Number of users, one address each, taken in order from samples/users.csv; the first quarter (at least two) are the busiest (4-40; client_first + user_count at most 255)
anonymizer_hosts[webproxy.hideme.example, free.unblocker.example, surf.anonymous.example, go.bypassgate.example]Hosts denied by Deny anonymizers (at least 3)
tunnel_hosts[dl.remotedesk.example, get.tunnelvpn.example, download.socksclient.example]Tunnel and remote-access client download hosts (at least 2)

Related Generators