Web & Access
Apache Tomcat JSON Access
Apache Tomcat 10.1 JsonAccessLogValve records for one application server, preserved in event.original and enriched with ECS fields.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/web-tomcat-json-access/generator.yml \
--id tomcat \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| success | Successful responses, redirects and 304 | 93.5% | web-access |
| missing | Missing resources | 2.2% | web-access |
| authentication | Authentication challenges | 1.9% | authentication |
| server-error | Application server errors | 1.3% | web-access |
| client-error | Other client errors | 1.1% | web-access |
Realism Features
- Native scalar values are strings; absent values and zero-byte bodies use a dash
- HTTP/1.1 request sizes and durations vary by class
- Manager Basic authentication uses no session ID
- Response bodies, deployment results and lifecycle logs are absent; ECS fields are enrichment
Sample Output
{
"@timestamp": "2026-09-01T00:00:02.000Z",
"apache_tomcat": {
"access": {
"elapsedTime": "23398",
"http": {
"ident": "-",
"useragent": "Go-http-client/2.0"
},
"localServerName": "tomcat-01.corp.example",
"logicalUserName": "-",
"sessionId": "-",
"user": "-"
}
},
"destination": {
"bytes": 556
},
"ecs": {
"version": "8.11.0"
},
"event": {
"category": [
"web"
],
"dataset": "apache_tomcat.access",
"duration": 23398000,
"kind": "event",
"module": "apache_tomcat",
"original": "{\"remoteAddr\":\"10.10.0.51\",\"logicalUserName\":\"-\",\"user\":\"-\",\"time\":\"[01/Sep/2026:00:00:02 +0000]\",\"request\":\"POST /api/v1/auth/token HTTP/1.1\",\"statusCode\":\"200\",\"size\":\"556\",\"elapsedTime\":\"23398\",\"sessionId\":\"-\",\"localServerName\":\"tomcat-01.corp.example\",\"requestHeaders\": {\"Referer\":\"-\",\"User-Agent\":\"Go-http-client/2.0\"}}",
"outcome": "success",
"type": [
"access"
]
},
"host": {
"hostname": "tomcat-01.corp.example",
"ip": [
"10.120.0.5"
],
"name": "tomcat-01.corp.example"
},
"http": {
"request": {
"method": "POST"
},
"response": {
"body": {
"bytes": 556
},
"status_code": 200
},
"version": "1.1"
},
"observer": {
"product": "Tomcat",
"type": "web",
"vendor": "Apache"
},
"related": {
"ip": [
"10.10.0.51"
]
},
"source": {
"address": "10.10.0.51",
"ip": "10.10.0.51"
},
"tags": [
"apache_tomcat-access",
"preserve_original_event"
],
"url": {
"original": "/api/v1/auth/token",
"path": "/api/v1/auth/token"
},
"user_agent": {
"original": "Go-http-client/2.0"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| server_name | tomcat-01.corp.example | Application server name |
| server_ip | 10.120.0.5 | Application server address |
| jvm_offset_minutes | 0 | Offset in the native access-log time |
| anomaly_mode | true | Include correlated manager requests |
| anomaly_interval_hours | 24 | Time between episode centers |
| anomaly_min_interval_hours | 1 | Lower interval bound |
| session_pool_cap | 200 | Maximum concurrent synthetic browser sessions |
Related Generators
Web & Access
Nginx Access & Error Logs
Nginx reverse proxy and web server — access logs with upstream timing, error logs with module context, bot/crawler traffic, scanner probes, and correlated 4xx/5xx error entries.
Web & Access
Apache HTTP Server
Apache httpd access and error logs — page/asset/API requests, bot crawlers (Googlebot, GPTBot), scanner probes, 3xx redirects, and correlated 4xx/5xx error log entries with module context.
Web & Access
Cisco AnyConnect VPN
Cisco ASA AnyConnect SSL VPN — session lifecycle from RADIUS authentication through tunnel establishment, IP assignment, DAP policy evaluation, session roaming between gateways, to graceful disconnection.