Staffcop Enterprise Syslog
Staffcop Enterprise 5.8 Syslog connector records in the native key-value format: Screenshot and Stat events from 40 employee workstations with the names of every policy each event matched, as native text in event.original with an inferred ECS mapping. For SIEM and UEBA rule authors; the optional CEF format is not emitted. About 8,600 records per weekday and 1,300 per weekend day follow an office working week. Recurring episodes show one finance employee capturing finance data with PrintScreen and then using cloud storage.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-staffcop-enterprise/generator.yml \
--id staffcop \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| Screenshot | Workstation screenshot, with zero or more matched policies | 88.7% of records | host |
| Stat | Activity statistics record closing a work bout in one application | 11.3% of records | host |
Realism Features
- 40 employees (10 finance, 9 sales, 9 development, 5 HR, 7 IT), each with a fixed workstation and address, work independently in bouts of one or more screenshots in one application, sometimes closed by a Stat record. The application mix depends on the department, and policy matches on the application and on whether the employee works with finance data. Finance workstations produce about a third of all records, about 1.6 times the per-employee volume of other departments.
- Finance staff regularly exchange documents through cloud storage in the browser: short bouts whose screenshots show a cloud storage page, often with finance documents, usually closed by a Stat that matches both policies (about 70 such Stat records per weekday across the department). Over a week the cloud storage policy matches 6.9% of records, finance data 6.5%, messengers 3.7%, PrintScreen 2.7% and social networks 2.3%; 81% of records match no policy, 16% one and 3% two or more.
- About 31 records an hour at night, about 140 in the 07:00 hour, about 500 in the 08:00, 13:00 and 18:00 hours and about 790 from 09:00 to 13:00 and 14:00 to 18:00 and 80-190 from 19:00 to 21:00 UTC on weekdays; weekend daytime holds about 78 an hour. Each employee's working day is shifted by up to 1.5 hours, so who is active follows the curve, not only how much is logged. Screenshots of one bout are a median of about one minute apart in office hours; at night they are about three minutes apart rather than about a minute.
- The volume follows one fixed weekly curve: no holidays, vacations, month-end peaks or differences between weekdays. Rates and probabilities are synthetic training assumptions, not measured Staffcop volume.
- The syslog header carries the connector dump time, advancing in steps of about 300 s as the vendor documents a dump once in 5 minutes; each record lands in the first dump after its agent upload delay (median 15 s, occasionally minutes). time and @timestamp hold the event time with second precision, event.created the dump time. The server id increases with random steps, since events of other types not selected by the connector filter consume ids too. Records are ordered by event time, while a real syslog file is ordered by dump time.
- With anomaly_mode true each episode has its own four records, so counts of the chain parts (finance, PrintScreen and cloud storage screenshots, Stat records with both policies) are about one per episode higher than with false. Policies are Staffcop matches, not proof of intent, and a policy count is not a severity scale.
- The vendor publishes three raw lines and no field specification, so only Screenshot and Stat are modelled; intercepted files, keyboard, web and other event classes are not, and application names follow the lowercase style of the vendor example. The policy_N order is random, day padding is assumed to be syslog space padding, and both clocks, which carry no year or time zone, are treated as UTC. The optional CEF export and SIEM-side normalizers are out of scope, and with no Elastic integration for Staffcop the ECS mapping is inferred (rule.name holds the matched policies).
Sample Output
{
"@timestamp": "2026-09-07T09:16:05+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "Stat",
"category": [
"host"
],
"created": "2026-09-07T09:19:07+00:00",
"dataset": "staffcop.syslog",
"id": "526503",
"kind": "event",
"original": "Sep 7 09:19:07 staffcop-srv staffcop: id=\"526503\" time=\"Sep 7 09:16:05\" event=\"Stat\" computer=\"WS-151\" ip=\"10.20.4.66\" user=\"e.kuznetsova\" app=\"chrome\" policy_1=\"\u0424\u0438\u043d\u0430\u043d\u0441\u043e\u0432\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435\" policy_2=\"\u041e\u0431\u043b\u0430\u0447\u043d\u044b\u0435 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430\"",
"type": [
"info"
]
},
"host": {
"ip": [
"10.20.4.66"
],
"name": "WS-151"
},
"log": {
"syslog": {
"appname": "staffcop",
"hostname": "staffcop-srv"
}
},
"observer": {
"hostname": "staffcop-srv",
"product": "Staffcop Enterprise",
"vendor": "Atom Security"
},
"process": {
"name": "chrome"
},
"related": {
"hosts": [
"WS-151"
],
"ip": [
"10.20.4.66"
],
"user": [
"e.kuznetsova"
]
},
"rule": {
"name": [
"\u0424\u0438\u043d\u0430\u043d\u0441\u043e\u0432\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435",
"\u041e\u0431\u043b\u0430\u0447\u043d\u044b\u0435 \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430"
]
},
"user": {
"name": "e.kuznetsova"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add periodic episodes to the background |
| anomaly_interval_hours | 24 | Episode interval in source hours, 2 to 8,760 |
| syslog_host | staffcop-srv | Staffcop server hostname in the syslog header and observer.hostname |
| policy_finance | Финансовые данные | Finance-data policy (chain steps 1 and 4) |
| policy_printscreen | Перехват PrintScreen | PrintScreen policy (chain step 2) |
| policy_cloud | Облачные хранилища | Cloud storage policy (chain steps 3 and 4) |
| policy_social | Социальные сети | Social networks policy (background) |
| policy_messengers | Мессенджеры | Messengers policy (background) |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.