OpenVPN Community Server Log
Server file log of one OpenVPN 2.6.14 Community remote-access server (verb 3, UDP, certificate authentication, no --duplicate-cn) as ECS JSON with each native line verbatim in event.original: connections from the TLS initial packet to the pushed data-channel options, duplicate-CN session replacements, clean exits and ping timeouts of 800 users. About 50,000 lines a day follow an office-hours curve in UTC. Recurring episodes show one certificate used from two places at once.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-openvpn-community/generator.yml \
--id openvpn \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| tls-initial-packet | TLS: Initial packet from the client address | 7.3% of lines | network |
| certificate-verified | VERIFY OK for the CA (depth=1) and the client (depth=0) | 14.6% of lines | authentication |
| control-channel-established | Control Channel: TLSv1.3 with peer certificate and peer temporary key | 7.3% of lines | network |
| peer-connection-initiated | [CN] Peer Connection Initiated | 7.3% of lines | session |
| virtual-address-assigned | MULTI_sva: pool returned IPv4 | 7.3% of lines | network |
| route-learned | MULTI: Learn: pool address -> CN/IP:port | 7.3% of lines | network |
| primary-virtual-address | MULTI: primary virtual IP | 7.3% of lines | network |
| push-request | PUSH: Received control message: PUSH_REQUEST | 7.3% of lines | network |
| data-channel-established | Data Channel: cipher AES-256-GCM, peer-id | 7.3% of lines | network |
| timers | Timers: ping 10, ping-restart 240 | 7.3% of lines | network |
| protocol-options | Protocol options: protocol-flags | 7.3% of lines | network |
| exit-scheduled | Delayed exit in 5 seconds after a client exit notification | 4.3% of lines | session |
| client-exited | SIGTERM[soft,delayed-exit] received, client-instance exiting | 4.3% of lines | session |
| duplicate-cn-replaced | MULTI: new connection by client CN will cause previous active sessions to be dropped | 1.8% of lines | session |
| inactivity-timeout | [CN] Inactivity timeout (--ping-restart), restarting | 1.2% of lines | session |
| client-restarted | SIGUSR1[soft,ping-restart] received, client-instance restarting | 1.2% of lines | session |
Realism Features
- Every line is YYYY-MM-DD HH:MM:SS <prefix> <text> in the server local time (UTC), with no syslog header; the prefix is the client IP:port before certificate verification and CN/IP:port after. event.original keeps the line, message drops the timestamp, and user.name is set only on lines that carry the client CN.
- About 50,000 lines a day (daily volume varies by about ±3%) on a stepped UTC office-hours curve: 0.15 lines/s at 23-07, 0.55 at 07-08 and 18-21, 1.0 at 08-18 and 0.30 at 21-23, with no weekday cycle. About 3,700 new connections a day, up to about 440 clients connected at the office-hours peak and up to about 35 lines of several clients in a busy second. The log starts with no clients connected.
- Each of the 800 users has a certificate CN, a persistent pool address in 10.8.0.0/22 and two or three usual public addresses: a unique home address, a mobile carrier address shared with a few other users and, for 37% of users, a shared branch-office NAT address. Users connect about 4.6 times a day on average, from about 1.5 times for the least active to about 14 for the most active; after a session a user stays offline for a lognormal pause (median 45 minutes divided by the activity weight, 0.35-4.0, at least 5 minutes).
- A session consists of segments: short (median about 2.5 minutes) on an unstable network, more likely right after a reconnect, and long otherwise (median 90 minutes divided by the activity weight). It ends with a clean exit, a vanished client (server ping timeout after 240 s) or a reconnect from the same or another of the user's networks, at once or after the client's 120 s ping-restart. A reconnect that reaches the server before the old instance times out replaces it and logs the duplicate-CN line; about a quarter of connections replace a live instance of the same CN.
- A client's connection lines fall within 0-3 s of its TLS: Initial packet line, SIGTERM follows Delayed exit in 5 seconds after exactly 5 s, and SIGUSR1 shares the second of its Inactivity timeout line. The server runs keepalive 10 120 (ping every 10 s, drop after 240 s, ping-restart 120 pushed to clients); peer-id is the lowest free slot, each CN keeps its pool address across sessions, and a replaced instance closes without a line of its own. The connection sequences of two new clients never overlap; reconnects and session ends interleave with them.
- Lines follow the format strings of the tagged 2.6.14 source, with TLS suite, key size, key-exchange group and protocol flags fixed for one OpenSSL 3 build and 2.6 clients; no raw log from a running server was available. Peer info, PUSH_REPLY, MTU and key lines, hourly TLS renegotiations and startup/status lines are omitted, as are failed verifications, tls-crypt unwrapping failures, TCP, IPv6 pools and --duplicate-cn servers. Most home addresses come from the benchmarking range 198.18.0.0/15, which does not occur on the public internet. All rates are synthetic.
- In ordinary traffic four alternating replacements of one CN never fall within ten minutes of the first, so a detector with fewer steps or a longer window also matches ordinary near misses. With anomaly_mode true, replacement counts are about four per episode higher than with false.
Sample Output
{
"@timestamp": "2026-09-01T11:47:19+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "duplicate-cn-replaced",
"category": [
"session"
],
"dataset": "openvpn.server",
"kind": "event",
"module": "openvpn",
"original": "2026-09-01 11:47:19 nikolai.hart/198.51.100.58:59766 MULTI: new connection by client \u0027nikolai.hart\u0027 will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.",
"type": [
"end"
]
},
"host": {
"name": "vpn-01"
},
"message": "nikolai.hart/198.51.100.58:59766 MULTI: new connection by client \u0027nikolai.hart\u0027 will cause previous active sessions by this client to be dropped. Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.",
"process": {
"name": "openvpn"
},
"related": {
"ip": [
"198.51.100.58"
],
"user": [
"nikolai.hart"
]
},
"source": {
"ip": "198.51.100.58",
"port": 59766
},
"user": {
"name": "nikolai.hart"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Emit recurring episodes; false gives background only |
| anomaly_interval_hours | 24 | Hours from one episode start to the next due time, 2 to 720 (a value outside stops generation with an error) |
| vpn_host | vpn-01 | host.name enrichment (the server's own lines carry no host name) |
| ca_common_name | Example Corp VPN CA | CN of the issuing CA in the depth=1 verification line |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.