Proxmox VE logs
About 12,240 records/day from one node, twelve VMs, administrators, automation accounts and an API-token monitor.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/virtualization-proxmox-ve/generator.yml \
--id proxmox \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| api-read | API request | 94.83% | configuration |
| ticket-issued | Authentication | 4.64% | authentication |
| ticket-denied | Authentication | 0.14% | authentication |
| vm-start-request | VM operation | 0.11% | configuration |
| vm-stop-request | VM operation | 0.06% | configuration |
| pveam-signature-verification | Appliance index update | 0.05% | configuration |
| vm-shutdown-request | VM operation | 0.05% | configuration |
| pveam-download-start | Appliance index update | 0.03% | configuration |
| pveam-download-finished | Appliance index update | 0.03% | configuration |
| vm-reboot-request | VM operation | 0.03% | configuration |
| pveam-update-successful | Appliance index update | 0.02% | configuration |
| pveam-update-start | Appliance index update | 0.01% | configuration |
Realism Features
- Human office hours and independent continuous monitoring
- VMs return to the running state on the ordinary restoration schedule
- Native lines with custom ECS enrichment; HTTP 200 confirms task submission
Sample Output
{
"@timestamp": "2026-09-01T03:13:28+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "vm-stop-request",
"category": [
"host"
],
"kind": "event",
"original": "::ffff:10.20.1.22 - backup-ops@pve [01/09/2026:03:13:28 +0000] \"POST /api2/json/nodes/pve-01/qemu/101/status/stop HTTP/1.1\" 200 76",
"outcome": "success",
"type": [
"change"
]
},
"host": {
"name": "pve-01"
},
"http": {
"request": {
"method": "POST"
},
"response": {
"body": {
"bytes": 76
},
"status_code": 200
},
"version": "1.1"
},
"log": {
"file": {
"path": "/var/log/pveproxy/access.log"
}
},
"proxmox": {
"access": {
"username": "backup-ops@pve"
}
},
"related": {
"ip": [
"10.20.1.22"
],
"user": [
"backup-ops@pve"
]
},
"source": {
"ip": "10.20.1.22"
},
"url": {
"path": "/api2/json/nodes/pve-01/qemu/101/status/stop"
},
"user": {
"name": "backup-ops@pve"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| node_name | pve-01 | Node name in native API paths and ECS host fields |
| anomaly_mode | true | Include correlated authentication and stop requests |
| anomaly_interval_hours | 24 | Recurrence interval, from 6 to 8760 hours |
Related Generators
VMware vCenter vpxd Events
VMware vCenter Server 8.0 vpxd events forwarded over RFC 5424 syslog and indexed by the Elastic VMware vSphere integration (vsphere.log): API logins and logouts, failed SSO logins, VM power and reconfiguration, and permission changes, with the native syslog line in event.original. About 8,100 records a day from one vCenter: four service accounts around the clock and eight staff accounts on a UTC working day. Recurring episodes show three to five failed SSO logins for one administrator, then that administrator's login and an Admin permission grant.
VMware ESXi hostd logs
ESXi 8 hostd authentication and VM tasks from one host, four administrators and two automated API clients. Native messages sit inside a custom ECS wrapper.
Microsoft Hyper-V VMMS Checkpoint and Merge Failures
Microsoft-Windows-Hyper-V-VMMS-Admin error records for failed VM checkpoints and background disk merges on four Hyper-V hosts with 60 VMs, as Winlogbeat-style ECS JSON with the raw Windows event XML in event.original. About 120 records a day, most of them in the nightly 22:00-05:00 backup window; ten VMs with recurring checkpoint trouble carry most failures. Recurring episodes show one of those VMs with a cancelled checkpoint followed by three failed checkpoint attempts, each followed by a disk merge failure.