Solar webProxy SIEM Log
Solar webProxy 4.3.1 request messages in the vendor siem-log syslog format from one filtering node in forward mode with TLS inspection serving 30 office users, as native text in event.original mapped to ECS. About 20,300 messages a day follow an office day in the node's local time (UTC+3). For testing web-proxy detections; models filtering decisions and traffic volumes, not administrator audit, access-log JSON, cef-log or ip-translation-log output. Recurring episodes show one user denied repeated uploads to a blocked file-sharing site, then uploading to sanctioned cloud storage.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/proxy-solar-webproxy/generator.yml \
--id solar-webproxy \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| page | Page and embedded-object GET to an allowed site (200, 304, 302, 404) | 84.5-85.3% of messages | web, network |
| poll | Application polling GET to JSON endpoints of business applications (200, 304) | 5.6-6.1% of messages | web, network |
| deny | GET to a blocked entertainment site, with user retries (403, URL block) | 3.5-4.0% of messages | web, network |
| api | Small POST to a business application (200, 201, 400) | 1.9-2.0% of messages | web, network |
| upload | POST upload to sanctioned cloud storage (200) | 1.9-2.1% of messages | web, network |
| download | GET download from cloud storage (200) | 1.3-1.4% of messages | web, network |
| share | POST upload to a blocked file-sharing site, occasionally retried (403, URL block) | 0.2-0.3% of messages | web, network |
Realism Features
- One filtering node serves 30 office users, about 20,300 messages a day, each daily total within about 3%. Volume follows the office day in the node's local time (UTC+3): about 120 messages an hour at night, 265 at 07:00 and 19:00, 815 at 08:00 and 18:00, 1,365 at 09:00 and 17:00, and 2,000 an hour from 10:00 to 17:00. Every day has the same shape, without weekends or holidays.
- Each user has a fixed activity weight (the busiest carry 4-12% of all messages, the quietest about 0.4%) and fixed working hours: a start between 07:00 and 10:00 local and a length of 8 to 10 hours, shifted each day (standard deviation about 35 minutes). About one day in ten a user is absent, about one day in three stays 0.5 to 3 hours late, and about one day in eight a workstation stays logged on overnight and keeps polling business applications. About 27 of the 30 users appear in each office hour and 4 to 11 at night.
- Blocked uploads number about 45-60 a day; about three quarters or more come from the six busiest users (4 to 10 a day each), each mostly to one habitual file-sharing site, and about one attempt in six is retried. A user refused twice on one site within 30 minutes usually makes no upload for the next 40 minutes to 2 hours. Outside episodes, no user makes an allowed upload to another host within 30 minutes of two or more denied uploads to one host.
- Blocked browsing, blocked uploads with retries, a single blocked upload followed by an upload to sanctioned storage, and repeated blocked uploads without any upload occur in ordinary traffic in both modes; with anomaly_mode false the ordinary traffic has the same mix. With anomaly_mode true each episode adds its own records, so counts of denied uploads and uploads to storage are a few records per episode higher.
- event.original follows table 9.2 and the raw example of the 4.3.1 installation manual: a syslog-ng header and 27 bracketed fields in the example's order, including acc-name and the bare [x-virus-id] marker. The header clock is local time, written when filtering ends, flt-time milliseconds after the UTC req-time, and its day is not zero-padded, as in the example.
- flt-codes values are copied from the vendor examples (11 for the decryption rule, 0 for layer transitions, 2 for the blocking rule), since the manual does not document the numeric mapping; flt-categories is 0 or one numeric category from the example. Blocked requests carry zero byte counts and application/skvt-unchecked, as in the vendor example; whether a blocked POST reports its partial body is not documented.
- Only URL-list blocks are modelled: antivirus, DLP, category, schedule and quota blocks, reverse-proxy mode and authentication failures are not generated. Traffic ratios are scenario choices, since Solar does not publish them; hosts use reserved test domains and documentation address ranges, and users and groups are synthetic. Compatibility with third-party siem-log normalizers has not been tested.
- Requests are seconds apart rather than milliseconds: the embedded objects of a page follow it after a median of about 6 seconds in office hours and about 70 seconds at night, where a browser fetches them within a second. The allowed upload of an episode comes within 25 minutes of the first denial; an ordinary upload after a single denial has no such limit (about 1% of them come later). The chain flags possible circumvention of an upload block; the log does not show file contents, so it is a correlation, not proof that the same data was uploaded.
Sample Output
{
"@timestamp": "2026-09-01T08:41:30.355+00:00",
"destination": {
"bytes": 649,
"domain": "disk.fabrikam.test",
"ip": "198.51.100.30",
"port": 443
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "http-allowed",
"category": [
"web",
"network"
],
"duration": 9000000,
"kind": "event",
"original": "Sep 1 11:41:30 wp-01 java: [acc-domain:CORP] [acc-groups:Employees] [acc-ip:10.20.4.25] [acc-name:e.popova] [acc-port:59633] [bytes-in:649] [bytes-out:320919] [flt-categories:0] [flt-codes:11,0,0,0,0,0] [flt-policy:\u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438] [flt-rules:https,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Request,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter req,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Response,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter resps,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e \u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438] [flt-status:200] [flt-time:9] [req-hostname:disk.fabrikam.test] [req-method:POST] [req-pathname:/api/v1/files/upload] [req-protocol:https] [req-query:] [req-referer:https://disk.fabrikam.test/] [req-time:2026-09-01T08:41:30.355Z] [req-user-agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36] [res-datatype:application/json] [res-ip:198.51.100.30] [traf-mode:forward] [x-virus-id] [req-port:443] [flt-reason:]",
"outcome": "success",
"type": [
"allowed",
"connection"
]
},
"host": {
"name": "wp-01"
},
"http": {
"request": {
"bytes": 320919,
"method": "POST",
"referrer": "https://disk.fabrikam.test/"
},
"response": {
"bytes": 649,
"mime_type": "application/json",
"status_code": 200
}
},
"observer": {
"hostname": "wp-01",
"product": "Solar webProxy",
"type": "proxy",
"vendor": "Solar"
},
"related": {
"hosts": [
"disk.fabrikam.test"
],
"ip": [
"10.20.4.25",
"198.51.100.30"
],
"user": [
"e.popova"
]
},
"rule": {
"name": "\u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438"
},
"solar_webproxy": {
"account_groups": "Employees",
"filter_categories": "0",
"filter_codes": "11,0,0,0,0,0",
"filter_policy": "\u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438",
"filter_reason": "",
"filter_rules": "https,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Request,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter req,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Icap Response,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e Filter resps,\u041f\u0435\u0440\u0435\u0445\u043e\u0434 \u043a \u0441\u043b\u043e\u044e \u0417\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u0435 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0438",
"filter_status": 200,
"filter_time_ms": 9,
"request_time": "2026-09-01T08:41:30.355Z",
"response_datatype": "application/json",
"traffic_mode": "forward"
},
"source": {
"bytes": 320919,
"ip": "10.20.4.25",
"port": 59633
},
"url": {
"domain": "disk.fabrikam.test",
"full": "https://disk.fabrikam.test/api/v1/files/upload",
"path": "/api/v1/files/upload",
"port": 443,
"scheme": "https"
},
"user": {
"domain": "CORP",
"group": {
"name": "Employees"
},
"name": "e.popova"
},
"user_agent": {
"original": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add recurring anomaly episodes; false produces background only |
| anomaly_interval_hours | 24 | Episode interval on source time, 1 to 8,760 hours |
| proxy_host | wp-01 | Host name in the syslog header |
| syslog_utc_offset_hours | 3 | Local time offset of the syslog header and of the users' working hours; req-time stays UTC. The hourly volume in patterns/ is set in UTC for an office at UTC+3: when changing the offset, shift the band hours in those files by the same amount |
| account_domain | CORP | acc-domain value |
| client_prefix | 10.20.4. | Prefix of user addresses |
| client_first | 21 | Last octet of the first user address; users get consecutive addresses (client_first plus the user count must stay at most 255) |
| users | 30 logins | acc-name values, at least 4 |
| groups | [Employees, Finance, Engineering, Sales] | acc-groups values, one per user, drawn at start with a skew toward the first |
| decrypt_rule | https | Name of the TLS inspection rule that leads flt-rules for HTTPS requests |
| block_layer | Restricted | Policy layer that blocks, written to flt-policy and flt-rules |
| sites | 8 sites | Allowed sites: host, address, flt-categories value, pages |
| blocked_sites | 3 sites | Blocked entertainment sites: host, address, category, blocking rule name, pages |
| sharing_sites | 3 sites | Blocked file-sharing sites: host, address, category, blocking rule name, upload path |
| storage_sites | 2 sites | Sanctioned cloud storage: host, address, category, upload path |
Related Generators
Nginx Access & Error Logs
Nginx reverse proxy and web server — access logs with upstream timing, error logs with module context, bot/crawler traffic, scanner probes, and correlated 4xx/5xx error entries.
Apache HTTP Server
Apache httpd access and error logs — page/asset/API requests, bot crawlers (Googlebot, GPTBot), scanner probes, 3xx redirects, and correlated 4xx/5xx error log entries with module context.
Cisco AnyConnect VPN
Cisco ASA AnyConnect SSL VPN — session lifecycle from RADIUS authentication through tunnel establishment, IP assignment, DAP policy evaluation, session roaming between gateways, to graceful disconnection.