Sign inSign up

archety/siem-log-simulator

By archety

•Updated about 1 month ago

Log Simulator API in Node.js for testing a SIEM in ELK

Image
Networking
Security
Languages & frameworks
0

194

archety/siem-log-simulator repository overview

⁠Log Simulator API

This guide explains how to run the Log Simulator API from a Docker image using terminal commands.

Repository:

johnnypax/siem-log-simulator⁠

Docker image used in the examples:

archety/siem-log-simulator:latest

This document is written for users who only have access to the Docker image and want to start containers from the terminal.

Default service URL:

http://localhost:3000

Default API prefix:

/api/v1

Health endpoint:

/health

⁠1. Pull The Image

docker pull archety/siem-log-simulator:latest

Verify the image:

docker images johnnypax/siem-log-simulator

⁠2. Run The Container

⁠2.1 Quick Start
docker run --rm \
  --name siem-log-simulator \
  -p 3000:3000 \
  archety/siem-log-simulator:latest

PowerShell:

docker run --rm `
  --name siem-log-simulator `
  -p 3000:3000 `
  archety/siem-log-simulator:latest

Check health:

curl http://localhost:3000/health
⁠2.2 Run Detached
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  archety/siem-log-simulator:latest

Follow container stdout/stderr:

docker logs -f siem-log-simulator

Stop and remove:

docker stop siem-log-simulator
docker rm siem-log-simulator

⁠3. Persistent Log Storage

The application writes simulated logs inside the container at:

/var/log/logsim

Use a Docker volume or a bind mount to keep generated logs.

⁠3.1 Named Volume
docker volume create logsim-data
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest

Inspect the volume:

docker volume inspect logsim-data

Remove the volume when no longer needed:

docker volume rm logsim-data
⁠3.2 Bind Mount - Linux/macOS
mkdir -p ./logs
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v "$(pwd)/logs:/var/log/logsim" \
  archety/siem-log-simulator:latest
⁠3.3 Bind Mount - PowerShell
New-Item -ItemType Directory -Force -Path .\logs | Out-Null
docker run -d `
  --name siem-log-simulator `
  -p 3000:3000 `
  -e LOG_DIRECTORY=/var/log/logsim `
  -v "${PWD}\logs:/var/log/logsim" `
  archety/siem-log-simulator:latest

⁠4. Common Runtime Modes

⁠4.1 Manual-Only Mode

Automatic generation is disabled. Use REST endpoints to generate logs.

docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e AUTO_ENABLED=false \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest
⁠4.2 Automatic Generation Mode
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e AUTO_ENABLED=true \
  -e AUTO_INTERVAL_MS=1000 \
  -e AUTO_EVENTS_PER_INTERVAL=5 \
  -e AUTO_PROFILES=ssh,firewall,webserver,application,dns,vpn,endpoint,ids \
  -e AUTO_PROFILE_WEIGHTS=ssh:25,firewall:20,webserver:20,application:10,dns:15,vpn:10,endpoint:15,ids:10 \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest
⁠4.3 ECS JSON Only

Useful for Elastic Common Schema ingestion tests.

docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e AUTO_ENABLED=true \
  -e AUTO_FORMAT_MODE=per-profile \
  -e LOG_FORMAT_SSH=ecs-json \
  -e LOG_FORMAT_FIREWALL=ecs-json \
  -e LOG_FORMAT_WEBSERVER=ecs-json \
  -e LOG_FORMAT_APPLICATION=ecs-json \
  -e LOG_FORMAT_DNS=ecs-json \
  -e LOG_FORMAT_VPN=ecs-json \
  -e LOG_FORMAT_ENDPOINT=ecs-json \
  -e LOG_FORMAT_IDS=ecs-json \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest
⁠4.4 JSON Lines Only
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e AUTO_ENABLED=true \
  -e AUTO_FORMAT_MODE=fixed \
  -e LOG_DEFAULT_FORMAT=json \
  -e LOG_FORMAT_SSH=json \
  -e LOG_FORMAT_FIREWALL=json \
  -e LOG_FORMAT_WEBSERVER=json \
  -e LOG_FORMAT_APPLICATION=json \
  -e LOG_FORMAT_DNS=json \
  -e LOG_FORMAT_VPN=json \
  -e LOG_FORMAT_ENDPOINT=json \
  -e LOG_FORMAT_IDS=json \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest
⁠4.5 Syslog And CEF Lab
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e AUTO_ENABLED=true \
  -e AUTO_FORMAT_MODE=per-profile \
  -e LOG_FORMAT_SSH=syslog-bsd \
  -e LOG_FORMAT_FIREWALL=cef \
  -e LOG_FORMAT_VPN=syslog-rfc5424 \
  -e LOG_FORMAT_IDS=cef \
  -e AUTO_PROFILES=ssh,firewall,vpn,ids \
  -e AUTO_PROFILE_WEIGHTS=ssh:25,firewall:25,vpn:25,ids:25 \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest
⁠4.6 Web Server Only
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e AUTO_ENABLED=true \
  -e AUTO_PROFILES=webserver \
  -e AUTO_PROFILE_WEIGHTS=webserver:100 \
  -e LOG_FORMAT_WEBSERVER=nginx-access \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest
⁠4.7 Security Devices Only
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e AUTO_ENABLED=true \
  -e AUTO_PROFILES=ssh,firewall,dns,vpn,endpoint,ids \
  -e AUTO_PROFILE_WEIGHTS=ssh:20,firewall:20,dns:15,vpn:15,endpoint:15,ids:15 \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest
⁠4.8 API Key Protected Mode
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e API_KEY_ENABLED=true \
  -e API_KEY=change-me \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest

Requests to /api/v1/* must include:

X-API-Key: change-me

/health remains public.

⁠5. Rotation Examples

⁠5.1 Production-Like Rotation
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e LOG_ROTATE_MAX_SIZE=20m \
  -e LOG_ROTATE_DAILY=true \
  -e LOG_ROTATE_MAX_FILES=14 \
  -e LOG_ROTATE_COMPRESS=true \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest

Example files:

ssh/syslog-bsd.log
ssh/syslog-bsd.2026-08-06.1.log.gz
ssh/syslog-bsd.2026-08-06.2.log.gz
⁠5.2 Fast Rotation Test
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e LOG_ROTATE_MAX_SIZE=1k \
  -e LOG_ROTATE_DAILY=true \
  -e LOG_ROTATE_MAX_FILES=3 \
  -e LOG_ROTATE_COMPRESS=false \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest

Then generate enough events:

curl -X POST http://localhost:3000/api/v1/events/application \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "unhandled-exception",
    "format": "application-text",
    "count": 100
  }'

⁠6. Log Layout Examples

⁠6.1 single-file
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e LOG_LAYOUT=single-file \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest

Output:

/var/log/logsim/events.log
⁠6.2 per-profile
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e LOG_LAYOUT=per-profile \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest

Output:

/var/log/logsim/ssh.log
/var/log/logsim/firewall.log
/var/log/logsim/webserver.log
/var/log/logsim/application.log
/var/log/logsim/dns.log
/var/log/logsim/vpn.log
/var/log/logsim/endpoint.log
/var/log/logsim/ids.log
⁠6.3 per-profile-format
docker run -d \
  --name siem-log-simulator \
  -p 3000:3000 \
  -e LOG_LAYOUT=per-profile-format \
  -e LOG_DIRECTORY=/var/log/logsim \
  -v logsim-data:/var/log/logsim \
  archety/siem-log-simulator:latest

Output:

/var/log/logsim/ssh/syslog-bsd.log
/var/log/logsim/firewall/cef.log
/var/log/logsim/webserver/nginx-access.log
/var/log/logsim/application/ecs-json.json
/var/log/logsim/dns/ecs-json.json
/var/log/logsim/vpn/syslog-rfc5424.log
/var/log/logsim/endpoint/ecs-json.json
/var/log/logsim/ids/cef.log

⁠7. Health And Inspection

⁠7.1 HTTP Health
curl http://localhost:3000/health

Example response:

{
  "status": "UP",
  "scheduler": "RUNNING",
  "eventsGenerated": 15420,
  "activeProfiles": ["ssh", "firewall", "webserver", "application", "dns", "vpn", "endpoint", "ids"]
}
⁠7.2 Docker Health Status
docker inspect --format='{{json .State.Health}}' siem-log-simulator

PowerShell:

docker inspect --format="{{json .State.Health}}" siem-log-simulator
⁠7.3 List Generated Files
docker exec siem-log-simulator find /var/log/logsim -maxdepth 4 -type f
⁠7.4 Tail A Specific Log
docker exec siem-log-simulator tail -n 20 /var/log/logsim/ssh/syslog-bsd.log
docker exec siem-log-simulator tail -n 20 /var/log/logsim/dns/ecs-json.json
docker exec siem-log-simulator tail -n 20 /var/log/logsim/ids/cef.log
⁠7.5 Copy Logs To The Host
docker cp siem-log-simulator:/var/log/logsim ./logsim-export

⁠8. API Examples Against The Container

All examples assume the container is running on:

http://localhost:3000
⁠8.1 Health
curl http://localhost:3000/health
⁠8.2 Profiles
curl http://localhost:3000/api/v1/profiles
⁠8.3 Stats
curl http://localhost:3000/api/v1/stats
⁠8.4 Scheduler Status
curl http://localhost:3000/api/v1/scheduler
⁠8.5 Start Scheduler
curl -X POST http://localhost:3000/api/v1/scheduler/start
⁠8.6 Stop Scheduler
curl -X POST http://localhost:3000/api/v1/scheduler/stop
⁠8.7 Runtime Config
curl http://localhost:3000/api/v1/config
⁠8.8 Patch Runtime Config
curl -X PATCH http://localhost:3000/api/v1/config \
  -H "Content-Type: application/json" \
  -d '{
    "auto": {
      "enabled": true,
      "eventsPerInterval": 10,
      "profiles": ["ssh", "firewall", "dns", "ids"],
      "profileWeights": {
        "ssh": 25,
        "firewall": 25,
        "dns": 25,
        "ids": 25
      }
    }
  }'

⁠9. Event Generation Examples

⁠9.1 SSH
curl -X POST http://localhost:3000/api/v1/events/ssh \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "failed-password",
    "format": "syslog-bsd",
    "count": 5,
    "sourceIp": "203.0.113.45",
    "username": "admin",
    "hostname": "bastion"
  }'
⁠9.2 Firewall
curl -X POST http://localhost:3000/api/v1/events/firewall \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "connection-denied",
    "format": "cef",
    "count": 5,
    "sourceIp": "203.0.113.77",
    "destinationIp": "10.10.0.10",
    "destinationPort": 443
  }'
⁠9.3 Web Server
curl -X POST http://localhost:3000/api/v1/events/webserver \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "http-403",
    "format": "nginx-access",
    "count": 5,
    "sourceIp": "203.0.113.88"
  }'
⁠9.4 Application
curl -X POST http://localhost:3000/api/v1/events/application \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "database-timeout",
    "format": "ecs-json",
    "count": 5,
    "service": "orders-api"
  }'
⁠9.5 DNS
curl -X POST http://localhost:3000/api/v1/events/dns \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "dns-tunneling-suspected",
    "format": "ecs-json",
    "count": 3,
    "sourceIp": "203.0.113.10"
  }'
⁠9.6 VPN
curl -X POST http://localhost:3000/api/v1/events/vpn \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "mfa-failed",
    "format": "syslog-rfc5424",
    "count": 3,
    "sourceIp": "203.0.113.22",
    "username": "admin"
  }'
⁠9.7 Endpoint / EDR
curl -X POST http://localhost:3000/api/v1/events/endpoint \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "malware-detected",
    "format": "json",
    "count": 2,
    "hostname": "win-hr-014",
    "username": "alice"
  }'
⁠9.8 IDS
curl -X POST http://localhost:3000/api/v1/events/ids \
  -H "Content-Type: application/json" \
  -d '{
    "eventType": "command-and-control-suspected",
    "format": "cef",
    "count": 3,
    "sourceIp": "203.0.113.99",
    "destinationIp": "10.10.0.20"
  }'

⁠10. Render-Only Examples

Render-only calls return generated lines without writing files.

⁠10.1 Render SSH As CEF
curl -X POST http://localhost:3000/api/v1/render \
  -H "Content-Type: application/json" \
  -d '{
    "profile": "ssh",
    "eventType": "failed-password",
    "format": "cef",
    "count": 3
  }'
⁠10.2 Render DNS As ECS JSON
curl -X POST http://localhost:3000/api/v1/render \
  -H "Content-Type: application/json" \
  -d '{
    "profile": "dns",
    "eventType": "query-blocked",
    "format": "ecs-json",
    "count": 2,
    "sourceIp": "203.0.113.10"
  }'
⁠10.3 Render IDS As CEF
curl -X POST http://localhost:3000/api/v1/render \
  -H "Content-Type: application/json" \
  -d '{
    "profile": "ids",
    "eventType": "exploit-attempt",
    "format": "cef",
    "count": 2
  }'

⁠11. Scenario Examples

⁠11.1 Brute Force
curl -X POST http://localhost:3000/api/v1/scenarios/brute-force \
  -H "Content-Type: application/json" \
  -d '{
    "durationSeconds": 20,
    "eventsPerSecond": 5,
    "sourceIp": "203.0.113.45",
    "format": "ecs-json"
  }'
⁠11.2 Port Scan
curl -X POST http://localhost:3000/api/v1/scenarios/port-scan \
  -H "Content-Type: application/json" \
  -d '{
    "durationSeconds": 15,
    "eventsPerSecond": 10,
    "sourceIp": "198.51.100.90",
    "destinationIp": "10.10.0.20",
    "format": "cef"
  }'
⁠11.3 Web Outage
curl -X POST http://localhost:3000/api/v1/scenarios/web-outage \
  -H "Content-Type: application/json" \
  -d '{
    "durationSeconds": 30,
    "eventsPerSecond": 8,
    "format": "nginx-access"
  }'
⁠11.4 Database Failure
curl -X POST http://localhost:3000/api/v1/scenarios/database-failure \
  -H "Content-Type: application/json" \
  -d '{
    "durationSeconds": 20,
    "eventsPerSecond": 5,
    "service": "orders-api",
    "format": "ecs-json"
  }'

⁠12. Supported Profiles And Formats

ProfileSupported formats
sshsyslog-bsd, syslog-rfc5424, json, ecs-json, cef
firewallsyslog-bsd, syslog-rfc5424, json, ecs-json, cef
webservernginx-access, nginx-error, json, ecs-json, cef
applicationapplication-text, json, ecs-json, cef
dnssyslog-bsd, syslog-rfc5424, json, ecs-json, cef
vpnsyslog-bsd, syslog-rfc5424, json, ecs-json, cef
endpointsyslog-bsd, syslog-rfc5424, json, ecs-json, cef
idssyslog-bsd, syslog-rfc5424, json, ecs-json, cef

Unsupported combinations return 422 Unprocessable Entity.

⁠13. Cleanup

Stop and remove the container:

docker stop siem-log-simulator
docker rm siem-log-simulator

Remove the named volume:

docker volume rm logsim-data

Remove exported logs:

rm -rf ./logsim-export

PowerShell:

Remove-Item -Recurse -Force .\logsim-export

⁠14. Troubleshooting

⁠14.1 The Image Cannot Be Pulled
docker pull archety/siem-log-simulator:latest

If the pull fails, check Docker Hub access, DNS, proxy settings, or registry authentication.

⁠14.2 The Container Is Running But The API Is Unreachable

Check that the port was published:

docker ps

The container should show:

0.0.0.0:3000->3000/tcp

Check logs:

docker logs siem-log-simulator
⁠14.3 No Files Are Generated

Check whether you called /api/v1/render. Render-only mode does not write files.

Check generated files:

docker exec siem-log-simulator find /var/log/logsim -maxdepth 4 -type f

Check scheduler status:

curl http://localhost:3000/api/v1/scheduler
⁠14.4 Permission Errors With Bind Mounts

The container runs as a non-root Node user. If bind mounts fail, use a named volume first:

docker volume create logsim-data
⁠14.5 API Key Errors

If API_KEY_ENABLED=true, send:

curl http://localhost:3000/api/v1/profiles \
  -H "X-API-Key: change-me"

⁠15. Quick Reference

docker pull archety/siem-log-simulator:latest
docker volume create logsim-data
docker run -d --name siem-log-simulator -p 3000:3000 -v logsim-data:/var/log/logsim archety/siem-log-simulator:latest
docker logs -f siem-log-simulator
docker exec siem-log-simulator find /var/log/logsim -maxdepth 4 -type f
curl http://localhost:3000/health
curl http://localhost:3000/api/v1/profiles
curl http://localhost:3000/api/v1/stats
docker stop siem-log-simulator
docker rm siem-log-simulator

⁠License

MIT License

Copyright (c) 2026 Giovanni Pace

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

⁠Coffeeware Philosophy

If this project helped you build something useful or learn something new, consider offering a coffee.

The best way to support my work is by subscribing to my YouTube channel:

https://youtube.com/@archety⁠

Tag summary

Content type

Image

Digest

sha256:ab9451c02…

Size

57.5 MB

Last updated

about 1 month ago

docker pull archety/siem-log-simulator