Stormshield SNS Audit Logs
Stormshield Network Security (SNS v4) audit records of one firewall separating office workstations from a server segment: IPS alarm 85 (interactive connection detected) from l_alarm and closed-connection records from l_connection, as ECS JSON with the native WELF key-value body in event.original. About 6,000 records a day follow an office day in UTC. Recurring episodes show one admin workstation opening interactive SSH sessions to three different servers, then pulling a bulk SSH transfer of 100 MiB or more.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-stormshield-sns/generator.yml \
--id stormshield \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| l_connection https | HTTPS connection closed (proto=https, port 443) | 65.0% of records | network |
| l_connection http | HTTP connection closed (proto=http, port 80) | 13.2% of records | network |
| l_connection ssh | SSH connection closed (proto=ssh, port 22) | 9.3% of records | network |
| l_alarm 85 | Alarm 85, interactive SSH connection detected (action=pass) | 7.4% of records | network, intrusion_detection |
| l_connection ntp | NTP exchange with the firewall (ipproto=udp, port 123) | 5.1% of records | network |
Realism Features
- About 6,000 records a day (+/- 3% from day to day) follow an office day in UTC: about 440 records an hour from 08:00 to 18:00, 200 an hour from 18:00 to 22:00 and 80 an hour at night. Every source is a workstation, so all traffic follows this curve.
- Admin workstations (10.10.5.11 and up, host objects adm_ws01...) run SSH work tasks weighted per workstation, the busiest doing up to four times the work of the quietest. A task opens one to six sessions to servers from the workstation's own set of 6-11 servers, each session starting up to 15 minutes after the previous one.
- An interactive session produces alarm 85 at its start and an l_connection record at close with startime, duration, sent and rcvd. About 20% of sessions are scp-style transfers with a log-normal received volume around 60 MB and no alarm, so transfers of 100 MiB and more occur in ordinary traffic (about 20 a day); that alarm 85 is not raised for transfers is a modelling assumption.
- Office workstations (10.10.1.20 and up, no host object) and admin workstations reach internal web servers over HTTPS and HTTP and synchronise time with the firewall. Host names, addresses, rule numbers, rates and volumes are synthetic, not measured SNS volumes.
- The vendor publishes one complete raw alarm line (alarm 85); the l_connection layout follows the SNS v4 field reference and lab syslog captures from the Elastic integration test fixtures. logtype is the family field of the syslog export, not part of the on-disk WELF files, and no syslog header is added.
- Only l_alarm alarm 85 and l_connection are generated: filter, authentication, web, VPN and system logs, other alarms and blocked traffic are out of scope. No address translation is modelled (modsrc and origdst equal src and dst), tz=+0000 with local time equal to UTC; SNS 5.x is not claimed.
- Records that coincide are logged one after another over the following seconds, so an admin session can be logged a few seconds late (median about 30 s, occasionally several minutes at night) and its duration includes that wait.
- An ordinary SSH transfer of 100 MiB or more that would complete the chain (about 13 a day) carries a smaller volume but keeps its original duration, so these transfers show a low throughput. With anomaly_mode true, alarm 85, SSH connection records and transfers of 100 MiB or more are each a few per episode higher than with false. The records show SSH sessions permitted by the filter policy, not authentication, lateral movement or data theft.
Sample Output
{
"@timestamp": "2026-09-02T16:46:59+00:00",
"destination": {
"bytes": 363275464,
"domain": "srv_app02",
"ip": "10.20.0.12",
"port": 22
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "connection_closed",
"category": [
"network"
],
"dataset": "stormshield.sns",
"duration": 11168025732,
"end": "2026-09-02T16:46:59+00:00",
"kind": "event",
"original": "id=firewall time=\"2026-09-02 16:46:59\" fw=\"sns-fw-01\" tz=+0000 startime=\"2026-09-02 16:46:48\" pri=5 confid=01 slotlevel=2 ruleid=5 srcif=\"Ethernet1\" srcifname=\"in\" ipproto=tcp proto=ssh src=10.10.5.13 srcport=14255 srcportname=ephemeral_fw srcname=adm_ws03 dst=10.20.0.12 dstport=22 dstportname=ssh dstname=srv_app02 modsrc=10.10.5.13 modsrcport=14255 origdst=10.20.0.12 origdstport=22 ipv=4 sent=9533853 rcvd=363275464 duration=11.16 action=pass logtype=\"connection\"",
"start": "2026-09-02T16:46:48+00:00",
"type": [
"connection",
"end",
"allowed"
]
},
"network": {
"bytes": 372809317,
"protocol": "ssh",
"transport": "tcp",
"type": "ipv4"
},
"observer": {
"ingress": {
"interface": {
"id": "Ethernet1",
"name": "in"
}
},
"name": "sns-fw-01",
"product": "SNS",
"type": "firewall",
"vendor": "Stormshield"
},
"related": {
"hosts": [
"adm_ws03",
"srv_app02"
],
"ip": [
"10.10.5.13",
"10.20.0.12"
]
},
"rule": {
"id": "5"
},
"source": {
"bytes": 9533853,
"ip": "10.10.5.13",
"port": 14255
},
"stormshield": {
"sns": {
"action": "pass",
"confid": "01",
"logtype": "connection",
"priority": 5,
"slotlevel": 2
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add the anomaly episodes to the background |
| anomaly_interval_hours | 24 | Source-time interval between episode starts, 2 to 8,760 |
| firewall_name | sns-fw-01 | Firewall name written to fw and observer.name |
| admin_count | 12 | Admin workstations (4-60), 10.10.5.11 upwards; the total admin work stays the same, so more workstations each do less |
| user_count | 40 | Office workstations (10-200), 10.10.1.20 upwards |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.