Windows RDP sessions
About 3,000 native XML and ECS records/day from one RDS host serving 200 accounts, including shift operators and shared jump hosts.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/windows-rdp-session-operational/generator.yml \
--id windows-rdp-session-operational \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 21 | Session logon succeeded | Per session lifecycle | session |
| 22 | Shell startup notification | Per session lifecycle | session |
| 23 | Session logoff succeeded | Per session lifecycle | session |
| 24 | Session disconnected | Per session lifecycle | session |
| 25 | Session reconnection succeeded | Per session lifecycle | session |
Realism Features
- Session logon, shell startup, disconnect, reconnect and logoff
- Sessions retain their user, address and ID until logoff
- Only successful remote sessions are included; a shared jump host can produce this pattern legitimately
Sample Output
{
"@timestamp": "2026-09-01T00:00:37.464584+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "session-logon",
"category": [
"authentication",
"session"
],
"code": "21",
"kind": "event",
"original": "<Event xmlns=\"http://schemas.microsoft.com/win/2004/08/events/event\"><System><Provider Name=\"Microsoft-Windows-TerminalServices-LocalSessionManager\" Guid=\"{5d896912-022d-40aa-a3a8-4fa5515c76d7}\"/><EventID>21</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x1000000000000000</Keywords><TimeCreated SystemTime=\"2026-09-01T00:00:37.4645845Z\"/><EventRecordID>40001</EventRecordID><Correlation ActivityID=\"{3b848838-005c-40b7-a0bf-283e9fb5c247}\"/><Execution ProcessID=\"3452\" ThreadID=\"432\"/><Channel>Microsoft-Windows-TerminalServices-LocalSessionManager/Operational</Channel><Computer>rds-01.corp.example</Computer><Security UserID=\"S-1-5-18\"/></System><UserData><EventXML xmlns=\"Event_NS\"><User>CORP\\operator156</User><SessionID>101</SessionID><Address>10.170.1.175</Address></EventXML></UserData></Event>",
"provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
"type": [
"start"
]
},
"host": {
"ip": [
"10.170.0.21"
],
"name": "rds-01.corp.example"
},
"log": {
"level": "information"
},
"related": {
"ip": [
"10.170.1.175"
],
"user": [
"CORP\\operator156"
]
},
"source": {
"ip": "10.170.1.175"
},
"user": {
"domain": "CORP",
"name": "operator156"
},
"winlog": {
"activity_id": "{3b848838-005c-40b7-a0bf-283e9fb5c247}",
"channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
"computer_name": "rds-01.corp.example",
"event_id": "21",
"process": {
"pid": 3452,
"thread": {
"id": 432
}
},
"provider_guid": "{5d896912-022d-40aa-a3a8-4fa5515c76d7}",
"provider_name": "Microsoft-Windows-TerminalServices-LocalSessionManager",
"record_id": 40001,
"user": {
"identifier": "S-1-5-18"
},
"user_data": {
"Address": "10.170.1.175",
"SessionID": "101",
"User": "CORP\\operator156",
"xml_name": "EventXML"
},
"version": 0
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| host_name | rds-01.corp.example | RDS host name |
| host_ip | 10.170.0.21 | RDS host address |
| anomaly_mode | true | Include recurring multi-account logon episodes |
| anomaly_interval_hours | 24 | Approximate interval between episode starts, from 6 to 8,760 hours |
Related Generators
Keycloak 26.7.4 Event Log
Keycloak 26.7.4 jboss-logging user and admin event lines for one realm with 1,500 users and 5 administrators, as native text in event.original with keycloak.*, user.*, source.* and url.* fields following the Elastic keycloak.log pipeline. Recurring episodes show one administrator failing five to eight logins from a VPN egress address, then logging in to the admin console and granting a privileged realm role.
Active Directory audit
About 21,800 normalized Security records per day from a small domain, with Kerberos, NTLM and temporary group membership.
ALD Pro domain controller
About 61,200 selected records/day from one domain controller, including native KDC, LDAP access and audit records.