Web & Access
Squid Native Access Log
Squid 6.x native access.log with stateful public-object caching, completion-time response bytes and recurring denied-to-allowed sequences.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/web-squid-access/generator.yml \
--id squid \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| TCP_MISS/200 or TCP_HIT/200 GET | Miss for a cold, expired or uncacheable URL; hit for a fresh cached object | 70% routine selection weight | web |
| TCP_TUNNEL/200 CONNECT | Tunnel to host and port, without path visibility | 18% routine selection weight | web |
| TCP_DENIED/403 or /407 GET | Restricted path; anonymous clients receive 407, and 10% of named 403 denials start a reload burst of one to four more denials | 7% routine selection weight; 7.0% 403 and 1.0% 407 of background records | web |
| TCP_IMS_HIT/304 GET | Conditional request for a cached object | 5% routine selection weight | web |
Realism Features
- Native epoch time is transaction completion, elapsed milliseconds map to ECS nanoseconds, and bytes include response headers delivered to the client. destination.bytes follows Elastic mapping, not origin traffic or upload volume.
- Only cacheable public resources can hit. Cache-Control public, max-age=3600, fixed headers, no Vary and no auth-dependent representation are explicit synthetic assumptions; hits reuse stored bytes until expiry.
- The cache holds at most 24 URLs, twelve shipped cacheable entries. Users reload blocked pages: runs of two to six denials of one user and URL within 31 seconds occur in background.
- Target client has an explicit 10% bias plus its share of the 24-client pool in both modes. The seven restricted URLs include the exact target; ordinary denials and successes overlap all sequence values.
- Full reference coverage is 43/54; selected 43/43 excludes eight GeoIP and three actual filesystem-identity fields. Collector IDs, offset and zero-delay ingestion are synthetic context.
- Exact Squid 6.9 TCP_IMS_HIT/304 raw record remains unavailable; historical native examples and tagged result definitions do not establish full same-version raw/parser compatibility. Usernames are ASCII tokens and URLs are HTTP without userinfo/query/fragment; arbitrary native quoting is outside this profile.
Sample Output
{
"@timestamp": "2026-09-01T01:13:35.589000+00:00",
"agent": {
"ephemeral_id": "5a110000-1111-4444-8888-123456789abc",
"id": "5a110000-1111-4444-8888-123456789abc",
"name": "squid-01",
"type": "filebeat",
"version": "8.17.0"
},
"data_stream": {
"dataset": "squid.log",
"namespace": "default",
"type": "logs"
},
"destination": {
"address": "10.70.8.14",
"bytes": 1891810,
"ip": "10.70.8.14"
},
"ecs": {
"version": "8.17.0"
},
"elastic_agent": {
"id": "5a110000-1111-4444-8888-123456789abc",
"snapshot": false,
"version": "8.17.0"
},
"event": {
"agent_id_status": "verified",
"category": [
"web"
],
"dataset": "squid.log",
"duration": 2188000000,
"ingested": "2026-09-01T01:13:35.589000+00:00",
"kind": "event",
"module": "squid",
"original": "1788225215.589 2188 10.70.4.17 TCP_MISS/200 1891810 GET http://files.corp.example/export.csv analyst HIER_DIRECT/10.70.8.14 text/csv",
"outcome": "success",
"type": [
"access"
]
},
"http": {
"request": {
"method": "GET"
}
},
"input": {
"type": "filestream"
},
"log": {
"file": {
"path": "/var/log/squid/access.log"
},
"offset": 116818
},
"observer": {
"hostname": "squid-01",
"ip": "10.70.0.5",
"product": "Squid",
"type": "proxy",
"vendor": "Squid"
},
"related": {
"hosts": [
"files.corp.example"
],
"ip": [
"10.70.4.17",
"10.70.8.14"
],
"user": [
"analyst"
]
},
"source": {
"address": "10.70.4.17",
"ip": "10.70.4.17",
"user": {
"name": "analyst"
}
},
"squid": {
"content_type": "text/csv",
"peer_status": "HIER_DIRECT",
"result_code": "TCP_MISS",
"status_code": 200
},
"tags": [
"preserve_original_event",
"squid-log"
],
"url": {
"domain": "files.corp.example",
"original": "http://files.corp.example/export.csv",
"path": "/export.csv",
"scheme": "http"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| proxy_name | squid-01 | Synthetic collector/proxy identity |
| proxy_ip | 10.70.0.5 | Synthetic collector/proxy identity |
| anomaly_user | analyst | Client identity in both background and sequence |
| anomaly_ip | 10.70.4.17 | Client identity in both background and sequence |
| anomaly_url | http://files.corp.example/export.csv | Absolute HTTP URL and origin used in both modes |
| anomaly_origin_ip | 10.70.8.14 | Absolute HTTP URL and origin used in both modes |
| anomaly_interval_hours | 6 | Mean time between episode starts, each within plus or minus min(interval / 8, 3 h) of its due time; values below one hour are clamped to one |
| anomaly_mode | true | Include repeated sequences; false emits background only |
Related Generators
Web & Access
Nginx Access & Error Logs
Nginx reverse proxy and web server — access logs with upstream timing, error logs with module context, bot/crawler traffic, scanner probes, and correlated 4xx/5xx error entries.
Web & Access
Apache HTTP Server
Apache httpd access and error logs — page/asset/API requests, bot crawlers (Googlebot, GPTBot), scanner probes, 3xx redirects, and correlated 4xx/5xx error log entries with module context.
Web & Access
Cisco AnyConnect VPN
Cisco ASA AnyConnect SSL VPN — session lifecycle from RADIUS authentication through tunnel establishment, IP assignment, DAP policy evaluation, session roaming between gateways, to graceful disconnection.