Hub
Web & Access

Solar webProxy SIEM Log

Solar webProxy 4.3.1 request messages in the vendor siem-log syslog format from one filtering node in forward mode with TLS inspection serving 30 office users, as native text in event.original mapped to ECS. About 20,300 messages a day follow an office day in the node's local time (UTC+3). For testing web-proxy detections; models filtering decisions and traffic volumes, not administrator audit, access-log JSON, cef-log or ip-translation-log output. Recurring episodes show one user denied repeated uploads to a blocked file-sharing site, then uploading to sanctioned cloud storage.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/proxy-solar-webproxy/generator.yml \
  --id solar-webproxy \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
pagePage and embedded-object GET to an allowed site (200, 304, 302, 404)84.5-85.3% of messagesweb, network
pollApplication polling GET to JSON endpoints of business applications (200, 304)5.6-6.1% of messagesweb, network
denyGET to a blocked entertainment site, with user retries (403, URL block)3.5-4.0% of messagesweb, network
apiSmall POST to a business application (200, 201, 400)1.9-2.0% of messagesweb, network
uploadPOST upload to sanctioned cloud storage (200)1.9-2.1% of messagesweb, network
downloadGET download from cloud storage (200)1.3-1.4% of messagesweb, network
sharePOST upload to a blocked file-sharing site, occasionally retried (403, URL block)0.2-0.3% of messagesweb, network

Realism Features

  • One filtering node serves 30 office users, about 20,300 messages a day, each daily total within about 3%. Volume follows the office day in the node's local time (UTC+3): about 120 messages an hour at night, 265 at 07:00 and 19:00, 815 at 08:00 and 18:00, 1,365 at 09:00 and 17:00, and 2,000 an hour from 10:00 to 17:00. Every day has the same shape, without weekends or holidays.
  • Each user has a fixed activity weight (the busiest carry 4-12% of all messages, the quietest about 0.4%) and fixed working hours: a start between 07:00 and 10:00 local and a length of 8 to 10 hours, shifted each day (standard deviation about 35 minutes). About one day in ten a user is absent, about one day in three stays 0.5 to 3 hours late, and about one day in eight a workstation stays logged on overnight and keeps polling business applications. About 27 of the 30 users appear in each office hour and 4 to 11 at night.
  • Blocked uploads number about 45-60 a day; about three quarters or more come from the six busiest users (4 to 10 a day each), each mostly to one habitual file-sharing site, and about one attempt in six is retried. A user refused twice on one site within 30 minutes usually makes no upload for the next 40 minutes to 2 hours. Outside episodes, no user makes an allowed upload to another host within 30 minutes of two or more denied uploads to one host.
  • Blocked browsing, blocked uploads with retries, a single blocked upload followed by an upload to sanctioned storage, and repeated blocked uploads without any upload occur in ordinary traffic in both modes; with anomaly_mode false the ordinary traffic has the same mix. With anomaly_mode true each episode adds its own records, so counts of denied uploads and uploads to storage are a few records per episode higher.
  • event.original follows table 9.2 and the raw example of the 4.3.1 installation manual: a syslog-ng header and 27 bracketed fields in the example's order, including acc-name and the bare [x-virus-id] marker. The header clock is local time, written when filtering ends, flt-time milliseconds after the UTC req-time, and its day is not zero-padded, as in the example.
  • flt-codes values are copied from the vendor examples (11 for the decryption rule, 0 for layer transitions, 2 for the blocking rule), since the manual does not document the numeric mapping; flt-categories is 0 or one numeric category from the example. Blocked requests carry zero byte counts and application/skvt-unchecked, as in the vendor example; whether a blocked POST reports its partial body is not documented.
  • Only URL-list blocks are modelled: antivirus, DLP, category, schedule and quota blocks, reverse-proxy mode and authentication failures are not generated. Traffic ratios are scenario choices, since Solar does not publish them; hosts use reserved test domains and documentation address ranges, and users and groups are synthetic. Compatibility with third-party siem-log normalizers has not been tested.
  • Requests are seconds apart rather than milliseconds: the embedded objects of a page follow it after a median of about 6 seconds in office hours and about 70 seconds at night, where a browser fetches them within a second. The allowed upload of an episode comes within 25 minutes of the first denial; an ordinary upload after a single denial has no such limit (about 1% of them come later). The chain flags possible circumvention of an upload block; the log does not show file contents, so it is a correlation, not proof that the same data was uploaded.

Sample Output

{
  "@timestamp": "2026-09-01T08:41:30.355+00:00",
  "destination": {
    "bytes": 649,
    "domain": "disk.fabrikam.test",
    "ip": "198.51.100.30",
    "port": 443
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "http-allowed",
    "category": [
      "web",
      "network"
    ],
    "duration": 9000000,
    "kind": "event",
    "original": "Sep 1 11:41:30 wp-01 java: [acc-domain:CORP] [acc-groups:Employees] [acc-ip:10.20.4.25] [acc-name:e.popova] [acc-port:59633] [bytes-in:649] [bytes-out:320919] [flt-categories:0] [flt-codes:11,0,0,0,0,0] [flt-policy:\u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438] [flt-rules:https,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Request,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter req,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Response,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter resps,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e \u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438] [flt-status:200] [flt-time:9] [req-hostname:disk.fabrikam.test] [req-method:POST] [req-pathname:/api/v1/files/upload] [req-protocol:https] [req-query:] [req-referer:https://disk.fabrikam.test/] [req-time:2026-09-01T08:41:30.355Z] [req-user-agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36] [res-datatype:application/json] [res-ip:198.51.100.30] [traf-mode:forward] [x-virus-id] [req-port:443] [flt-reason:]",
    "outcome": "success",
    "type": [
      "allowed",
      "connection"
    ]
  },
  "host": {
    "name": "wp-01"
  },
  "http": {
    "request": {
      "bytes": 320919,
      "method": "POST",
      "referrer": "https://disk.fabrikam.test/"
    },
    "response": {
      "bytes": 649,
      "mime_type": "application/json",
      "status_code": 200
    }
  },
  "observer": {
    "hostname": "wp-01",
    "product": "Solar webProxy",
    "type": "proxy",
    "vendor": "Solar"
  },
  "related": {
    "hosts": [
      "disk.fabrikam.test"
    ],
    "ip": [
      "10.20.4.25",
      "198.51.100.30"
    ],
    "user": [
      "e.popova"
    ]
  },
  "rule": {
    "name": "\u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438"
  },
  "solar_webproxy": {
    "account_groups": "Employees",
    "filter_categories": "0",
    "filter_codes": "11,0,0,0,0,0",
    "filter_policy": "\u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438",
    "filter_reason": "",
    "filter_rules": "https,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Request,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter req,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Response,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter resps,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e \u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438",
    "filter_status": 200,
    "filter_time_ms": 9,
    "request_time": "2026-09-01T08:41:30.355Z",
    "response_datatype": "application/json",
    "traffic_mode": "forward"
  },
  "source": {
    "bytes": 320919,
    "ip": "10.20.4.25",
    "port": 59633
  },
  "url": {
    "domain": "disk.fabrikam.test",
    "full": "https://disk.fabrikam.test/api/v1/files/upload",
    "path": "/api/v1/files/upload",
    "port": 443,
    "scheme": "https"
  },
  "user": {
    "domain": "CORP",
    "group": {
      "name": "Employees"
    },
    "name": "e.popova"
  },
  "user_agent": {
    "original": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd recurring anomaly episodes; false produces background only
anomaly_interval_hours24Episode interval on source time, 1 to 8,760 hours
proxy_hostwp-01Host name in the syslog header
syslog_utc_offset_hours3Local time offset of the syslog header and of the users' working hours; req-time stays UTC. The hourly volume in patterns/ is set in UTC for an office at UTC+3: when changing the offset, shift the band hours in those files by the same amount
account_domainCORPacc-domain value
client_prefix10.20.4.Prefix of user addresses
client_first21Last octet of the first user address; users get consecutive addresses (client_first plus the user count must stay at most 255)
users30 loginsacc-name values, at least 4
groups[Employees, Finance, Engineering, Sales]acc-groups values, one per user, drawn at start with a skew toward the first
decrypt_rulehttpsName of the TLS inspection rule that leads flt-rules for HTTPS requests
block_layerRestrictedPolicy layer that blocks, written to flt-policy and flt-rules
sites8 sitesAllowed sites: host, address, flt-categories value, pages
blocked_sites3 sitesBlocked entertainment sites: host, address, category, blocking rule name, pages
sharing_sites3 sitesBlocked file-sharing sites: host, address, category, blocking rule name, upload path
storage_sites2 sitesSanctioned cloud storage: host, address, category, upload path

Related Generators