Hub
Network

OpenVPN Community Server Log

Server file log of one OpenVPN 2.6.14 Community remote-access server (verb 3, UDP, certificate authentication, no --duplicate-cn) as ECS JSON with each native line verbatim in event.original: connections from the TLS initial packet to the pushed data-channel options, duplicate-CN session replacements, clean exits and ping timeouts of 800 users. About 50,000 lines a day follow an office-hours curve in UTC. Recurring episodes show one certificate used from two places at once.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/network-openvpn-community/generator.yml \
  --id openvpn \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
tls-initial-packetTLS: Initial packet from the client address7.3% of linesnetwork
certificate-verifiedVERIFY OK for the CA (depth=1) and the client (depth=0)14.6% of linesauthentication
control-channel-establishedControl Channel: TLSv1.3 with peer certificate and peer temporary key7.3% of linesnetwork
peer-connection-initiated[CN] Peer Connection Initiated7.3% of linessession
virtual-address-assignedMULTI_sva: pool returned IPv47.3% of linesnetwork
route-learnedMULTI: Learn: pool address -> CN/IP:port7.3% of linesnetwork
primary-virtual-addressMULTI: primary virtual IP7.3% of linesnetwork
push-requestPUSH: Received control message: PUSH_REQUEST7.3% of linesnetwork
data-channel-establishedData Channel: cipher AES-256-GCM, peer-id7.3% of linesnetwork
timersTimers: ping 10, ping-restart 2407.3% of linesnetwork
protocol-optionsProtocol options: protocol-flags7.3% of linesnetwork
exit-scheduledDelayed exit in 5 seconds after a client exit notification4.3% of linessession
client-exitedSIGTERM[soft,delayed-exit] received, client-instance exiting4.3% of linessession
duplicate-cn-replacedMULTI: new connection by client CN will cause previous active sessions to be dropped1.8% of linessession
inactivity-timeout[CN] Inactivity timeout (--ping-restart), restarting1.2% of linessession
client-restartedSIGUSR1[soft,ping-restart] received, client-instance restarting1.2% of linessession

Realism Features

  • Every line is YYYY-MM-DD HH:MM:SS <prefix> <text> in the server local time (UTC), with no syslog header; the prefix is the client IP:port before certificate verification and CN/IP:port after. event.original keeps the line, message drops the timestamp, and user.name is set only on lines that carry the client CN.
  • About 50,000 lines a day (daily volume varies by about ±3%) on a stepped UTC office-hours curve: 0.15 lines/s at 23-07, 0.55 at 07-08 and 18-21, 1.0 at 08-18 and 0.30 at 21-23, with no weekday cycle. About 3,700 new connections a day, up to about 440 clients connected at the office-hours peak and up to about 35 lines of several clients in a busy second. The log starts with no clients connected.
  • Each of the 800 users has a certificate CN, a persistent pool address in 10.8.0.0/22 and two or three usual public addresses: a unique home address, a mobile carrier address shared with a few other users and, for 37% of users, a shared branch-office NAT address. Users connect about 4.6 times a day on average, from about 1.5 times for the least active to about 14 for the most active; after a session a user stays offline for a lognormal pause (median 45 minutes divided by the activity weight, 0.35-4.0, at least 5 minutes).
  • A session consists of segments: short (median about 2.5 minutes) on an unstable network, more likely right after a reconnect, and long otherwise (median 90 minutes divided by the activity weight). It ends with a clean exit, a vanished client (server ping timeout after 240 s) or a reconnect from the same or another of the user's networks, at once or after the client's 120 s ping-restart. A reconnect that reaches the server before the old instance times out replaces it and logs the duplicate-CN line; about a quarter of connections replace a live instance of the same CN.
  • A client's connection lines fall within 0-3 s of its TLS: Initial packet line, SIGTERM follows Delayed exit in 5 seconds after exactly 5 s, and SIGUSR1 shares the second of its Inactivity timeout line. The server runs keepalive 10 120 (ping every 10 s, drop after 240 s, ping-restart 120 pushed to clients); peer-id is the lowest free slot, each CN keeps its pool address across sessions, and a replaced instance closes without a line of its own. The connection sequences of two new clients never overlap; reconnects and session ends interleave with them.
  • Lines follow the format strings of the tagged 2.6.14 source, with TLS suite, key size, key-exchange group and protocol flags fixed for one OpenSSL 3 build and 2.6 clients; no raw log from a running server was available. Peer info, PUSH_REPLY, MTU and key lines, hourly TLS renegotiations and startup/status lines are omitted, as are failed verifications, tls-crypt unwrapping failures, TCP, IPv6 pools and --duplicate-cn servers. Most home addresses come from the benchmarking range 198.18.0.0/15, which does not occur on the public internet. All rates are synthetic.
  • In ordinary traffic four alternating replacements of one CN never fall within ten minutes of the first, so a detector with fewer steps or a longer window also matches ordinary near misses. With anomaly_mode true, replacement counts are about four per episode higher than with false.

Sample Output

{
  "@timestamp": "2026-09-01T11:47:19+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "duplicate-cn-replaced",
    "category": [
      "session"
    ],
    "dataset": "openvpn.server",
    "kind": "event",
    "module": "openvpn",
    "original": "2026-09-01 11:47:19 nikolai.hart/198.51.100.58:59766 MULTI: new connection by client \u0027nikolai.hart\u0027 will cause previous active sessions by this client to be dropped.  Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.",
    "type": [
      "end"
    ]
  },
  "host": {
    "name": "vpn-01"
  },
  "message": "nikolai.hart/198.51.100.58:59766 MULTI: new connection by client \u0027nikolai.hart\u0027 will cause previous active sessions by this client to be dropped.  Remember to use the --duplicate-cn option if you want multiple clients using the same certificate or username to concurrently connect.",
  "process": {
    "name": "openvpn"
  },
  "related": {
    "ip": [
      "198.51.100.58"
    ],
    "user": [
      "nikolai.hart"
    ]
  },
  "source": {
    "ip": "198.51.100.58",
    "port": 59766
  },
  "user": {
    "name": "nikolai.hart"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueEmit recurring episodes; false gives background only
anomaly_interval_hours24Hours from one episode start to the next due time, 2 to 720 (a value outside stops generation with an error)
vpn_hostvpn-01host.name enrichment (the server's own lines carry no host name)
ca_common_nameExample Corp VPN CACN of the issuing CA in the depth=1 verification line

Related Generators