Hub
Web & Access

Squid Native Access Log

Squid 6.x native access.log with stateful public-object caching, completion-time response bytes and recurring denied-to-allowed sequences.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/web-squid-access/generator.yml \
  --id squid \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
TCP_MISS/200 or TCP_HIT/200 GETMiss for a cold, expired or uncacheable URL; hit for a fresh cached object70% routine selection weightweb
TCP_TUNNEL/200 CONNECTTunnel to host and port, without path visibility18% routine selection weightweb
TCP_DENIED/403 or /407 GETRestricted path; anonymous clients receive 407, and 10% of named 403 denials start a reload burst of one to four more denials7% routine selection weight; 7.0% 403 and 1.0% 407 of background recordsweb
TCP_IMS_HIT/304 GETConditional request for a cached object5% routine selection weightweb

Realism Features

  • Native epoch time is transaction completion, elapsed milliseconds map to ECS nanoseconds, and bytes include response headers delivered to the client. destination.bytes follows Elastic mapping, not origin traffic or upload volume.
  • Only cacheable public resources can hit. Cache-Control public, max-age=3600, fixed headers, no Vary and no auth-dependent representation are explicit synthetic assumptions; hits reuse stored bytes until expiry.
  • The cache holds at most 24 URLs, twelve shipped cacheable entries. Users reload blocked pages: runs of two to six denials of one user and URL within 31 seconds occur in background.
  • Target client has an explicit 10% bias plus its share of the 24-client pool in both modes. The seven restricted URLs include the exact target; ordinary denials and successes overlap all sequence values.
  • Full reference coverage is 43/54; selected 43/43 excludes eight GeoIP and three actual filesystem-identity fields. Collector IDs, offset and zero-delay ingestion are synthetic context.
  • Exact Squid 6.9 TCP_IMS_HIT/304 raw record remains unavailable; historical native examples and tagged result definitions do not establish full same-version raw/parser compatibility. Usernames are ASCII tokens and URLs are HTTP without userinfo/query/fragment; arbitrary native quoting is outside this profile.

Sample Output

{
  "@timestamp": "2026-09-01T01:13:35.589000+00:00",
  "agent": {
    "ephemeral_id": "5a110000-1111-4444-8888-123456789abc",
    "id": "5a110000-1111-4444-8888-123456789abc",
    "name": "squid-01",
    "type": "filebeat",
    "version": "8.17.0"
  },
  "data_stream": {
    "dataset": "squid.log",
    "namespace": "default",
    "type": "logs"
  },
  "destination": {
    "address": "10.70.8.14",
    "bytes": 1891810,
    "ip": "10.70.8.14"
  },
  "ecs": {
    "version": "8.17.0"
  },
  "elastic_agent": {
    "id": "5a110000-1111-4444-8888-123456789abc",
    "snapshot": false,
    "version": "8.17.0"
  },
  "event": {
    "agent_id_status": "verified",
    "category": [
      "web"
    ],
    "dataset": "squid.log",
    "duration": 2188000000,
    "ingested": "2026-09-01T01:13:35.589000+00:00",
    "kind": "event",
    "module": "squid",
    "original": "1788225215.589   2188 10.70.4.17 TCP_MISS/200 1891810 GET http://files.corp.example/export.csv analyst HIER_DIRECT/10.70.8.14 text/csv",
    "outcome": "success",
    "type": [
      "access"
    ]
  },
  "http": {
    "request": {
      "method": "GET"
    }
  },
  "input": {
    "type": "filestream"
  },
  "log": {
    "file": {
      "path": "/var/log/squid/access.log"
    },
    "offset": 116818
  },
  "observer": {
    "hostname": "squid-01",
    "ip": "10.70.0.5",
    "product": "Squid",
    "type": "proxy",
    "vendor": "Squid"
  },
  "related": {
    "hosts": [
      "files.corp.example"
    ],
    "ip": [
      "10.70.4.17",
      "10.70.8.14"
    ],
    "user": [
      "analyst"
    ]
  },
  "source": {
    "address": "10.70.4.17",
    "ip": "10.70.4.17",
    "user": {
      "name": "analyst"
    }
  },
  "squid": {
    "content_type": "text/csv",
    "peer_status": "HIER_DIRECT",
    "result_code": "TCP_MISS",
    "status_code": 200
  },
  "tags": [
    "preserve_original_event",
    "squid-log"
  ],
  "url": {
    "domain": "files.corp.example",
    "original": "http://files.corp.example/export.csv",
    "path": "/export.csv",
    "scheme": "http"
  }
}

Parameters

ParameterDefaultDescription
proxy_namesquid-01Synthetic collector/proxy identity
proxy_ip10.70.0.5Synthetic collector/proxy identity
anomaly_useranalystClient identity in both background and sequence
anomaly_ip10.70.4.17Client identity in both background and sequence
anomaly_urlhttp://files.corp.example/export.csvAbsolute HTTP URL and origin used in both modes
anomaly_origin_ip10.70.8.14Absolute HTTP URL and origin used in both modes
anomaly_interval_hours6Mean time between episode starts, each within plus or minus min(interval / 8, 3 h) of its due time; values below one hour are clamped to one
anomaly_modetrueInclude repeated sequences; false emits background only

Related Generators