Hub
Application

Atlassian Jira security logs

About 6,600 records/day from one Jira node and 512 accounts, with native security messages and ECS enrichment.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/web-atlassian-jira-security/generator.yml \
  --id jira-security \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
session-createdsession created42.55%Session lifecycle
session-destroyedsession destroyed28.35%Session lifecycle
authentication-passedauthentication passed14.19%Authentication
logoutlogout14.15%Authentication
authentication-failedauthentication failed0.64%Authentication
captcha-requiredcaptcha required0.11%Authentication

Realism Features

  • Office-hour activity, account-wide failure counts and overlapping authenticated sessions
  • Login and logout preserve request IDs and session replacement records
  • The retry sequence alone does not prove compromise

Sample Output

{
  "@timestamp": "2026-09-01T00:01:23.300000+00:00",
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "authentication-passed",
    "category": [
      "authentication"
    ],
    "kind": "event",
    "original": "2026-09-01 00:01:23,300+0000 http-nio-8080-exec-8 url: /jira/login.jsp user0029 0x103x1 4mk6er2 10.20.10.29 /login.jsp The user \u0027user0029\u0027 has PASSED authentication.",
    "outcome": "success",
    "type": [
      "start"
    ]
  },
  "host": {
    "name": "jira-dc-01.example.test"
  },
  "jira": {
    "security": {
      "context_url": "/jira/login.jsp",
      "message": "The user \u0027user0029\u0027 has PASSED authentication.",
      "request_id": "0x103x1",
      "request_url": "/login.jsp",
      "session_id": "4mk6er2",
      "target_user": "user0029"
    }
  },
  "log": {
    "file": {
      "path": "atlassian-jira-security.log"
    }
  },
  "process": {
    "thread": {
      "name": "http-nio-8080-exec-8"
    }
  },
  "related": {
    "ip": [
      "10.20.10.29"
    ],
    "user": [
      "user0029"
    ]
  },
  "source": {
    "ip": "10.20.10.29"
  },
  "user": {
    "name": "user0029"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueInclude the recurring retry sequence
anomaly_interval_hours24Recurrence interval, from 1 to 8760 hours
host_namejira-dc-01.example.testJira node name in the ECS wrapper
context_path/jiraApplication context in the thread's request URL

Related Generators

Application

1C:Enterprise Event Log

1C:Enterprise 8.3.27 event-log collector projection for a client/server, single-data-area infobase: ECS-style JSON with snake_case source fields under one_c.event_log, not a native XML or .lgf export and without event.original. Six staff accounts, four reusable temporary account names and five configured objects with explicit permissions. Recurring episodes, weekly by default, join an administrator's failed logins, a temporary FullAccess account, its payroll reads, its deletion and an event-log reduction.

Application

1C:Enterprise Technological Log

1C:Enterprise 8.3.27 technological-log JSON records (SCALL, CALL, TLOCK, EXCP) of one rphost process serving fourteen client and service sessions of one infobase, in an ECS envelope. About 44,000 records a day: interactive users follow a working day in UTC, background jobs keep the same pace day and night. Managed locks on document keys are granted at once, queued, or time out after 20 seconds. Recurring episodes are lock convoys: one very long posting blocks a busy document key until six distinct sessions have timed out on it within 50 minutes.

Application

Nextcloud Admin Audit

Nextcloud 35.0.0 admin_audit HTTP records from the dedicated audit.log file backend, with each native JSON line in event.original and parsed under nextcloud.audit, for testing detections on logins, file access and public links. 180 users work in sessions over 1,154 files, about 10,800 records a day. Recurring episodes show a guessed password followed by publishing a file for outside access through a public link.