Hub
Virtualization

Proxmox VE logs

About 12,240 records/day from one node, twelve VMs, administrators, automation accounts and an API-token monitor.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/virtualization-proxmox-ve/generator.yml \
  --id proxmox \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
api-readAPI request94.83%configuration
ticket-issuedAuthentication4.64%authentication
ticket-deniedAuthentication0.14%authentication
vm-start-requestVM operation0.11%configuration
vm-stop-requestVM operation0.06%configuration
pveam-signature-verificationAppliance index update0.05%configuration
vm-shutdown-requestVM operation0.05%configuration
pveam-download-startAppliance index update0.03%configuration
pveam-download-finishedAppliance index update0.03%configuration
vm-reboot-requestVM operation0.03%configuration
pveam-update-successfulAppliance index update0.02%configuration
pveam-update-startAppliance index update0.01%configuration

Realism Features

  • Human office hours and independent continuous monitoring
  • VMs return to the running state on the ordinary restoration schedule
  • Native lines with custom ECS enrichment; HTTP 200 confirms task submission

Sample Output

{
  "@timestamp": "2026-09-01T03:13:28+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "vm-stop-request",
    "category": [
      "host"
    ],
    "kind": "event",
    "original": "::ffff:10.20.1.22 - backup-ops@pve [01/09/2026:03:13:28 +0000] \"POST /api2/json/nodes/pve-01/qemu/101/status/stop HTTP/1.1\" 200 76",
    "outcome": "success",
    "type": [
      "change"
    ]
  },
  "host": {
    "name": "pve-01"
  },
  "http": {
    "request": {
      "method": "POST"
    },
    "response": {
      "body": {
        "bytes": 76
      },
      "status_code": 200
    },
    "version": "1.1"
  },
  "log": {
    "file": {
      "path": "/var/log/pveproxy/access.log"
    }
  },
  "proxmox": {
    "access": {
      "username": "backup-ops@pve"
    }
  },
  "related": {
    "ip": [
      "10.20.1.22"
    ],
    "user": [
      "backup-ops@pve"
    ]
  },
  "source": {
    "ip": "10.20.1.22"
  },
  "url": {
    "path": "/api2/json/nodes/pve-01/qemu/101/status/stop"
  },
  "user": {
    "name": "backup-ops@pve"
  }
}

Parameters

ParameterDefaultDescription
node_namepve-01Node name in native API paths and ECS host fields
anomaly_modetrueInclude correlated authentication and stop requests
anomaly_interval_hours24Recurrence interval, from 6 to 8760 hours

Related Generators