Skip to content

Latest commit

Β 

History

18 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ SIEM Log Generator β€” Praharsh Edition

Typing SVG

πŸ”₯ 3,000+ Realistic Security Events | 🎯 30+ MITRE ATT&CK Techniques | πŸ–₯️ 4 SIEM Output Formats


πŸ‘€ Author

Praharsh Kumar SOC Analyst | Detection Engineer | Multi-SIEM Lab Builder

LinkedIn GitHub


πŸ“‹ Overview

This is my personal SIEM log generator, built for my Multi-VM SOC Lab. I use this to practice threat hunting, build detection rules, and test my Splunk, Wazuh, ELK, and Microsoft Sentinel setups.

Unlike generic log generators, this one is built around a real lab environment β€” the IPs, hostnames, attack techniques, and tool names all match what I actually run in my lab.

πŸ–₯️ My Lab Setup

Kali Linux (Attacker)    β†’ 192.168.66.104
Windows 10 VM (Target)   β†’ 192.168.66.105
Splunk Enterprise VM     β†’ 192.168.56.101
Wazuh Manager VM         β†’ 192.168.66.102
ELK Stack VM             β†’ 192.168.66.103

⚑ Features

What Makes This Different

Feature Generic Generators This Project
Output formats JSON + CSV only JSON + CSV + Wazuh + Sentinel
Lab IPs Generic/random Your actual lab IPs
Attack tools Not specified Hydra, Mimikatz, Metasploit, Nmap
Sysmon events Basic Event IDs 1, 3, 7, 8, 11, 13
Wazuh format ❌ βœ… Rule levels + Agent info
Sentinel format ❌ βœ… KQL-ready fields
MITRE coverage ~15 techniques 30+ techniques
Event count 2,500 3,000+

🎯 Event Categories

Category Event Types MITRE Techniques
πŸ” Authentication Failed Login, Brute Force, RDP BF, SSH BF, Password Spray, Kerberoasting T1110, T1558
πŸ’» Sysmon Process Create, Network Conn, Image Load, File Create, Registry Set T1003, T1055, T1547
🐚 Execution Reverse Shell, PowerShell, LOLBIN, WMI T1059, T1218, T1047
πŸ”Ό Privilege Esc Token Impersonation, SeDebugPrivilege T1068
🌐 Lateral Movement RDP, PsExec, WMI Remote T1021, T1570
πŸ“€ C2 & Exfil C2 Outbound, DNS Tunneling, Data Transfer T1071, T1048
πŸ›‘οΈ Endpoint Mimikatz, Process Injection, Malware, Ransomware T1003, T1055, T1486
☁️ Cloud IAM Abuse, Impossible Travel T1098, T1078.004
🌊 Network Firewall Blocks, Port Scans (Nmap), IDS Alerts T1046
πŸ“§ Email Phishing, Malicious Attachments T1566
πŸ”” Wazuh Rule-based alerts from Wazuh Manager Various

πŸš€ Quick Start

Requirements

  • Python 3.8+
  • No external dependencies (standard library only)

Run

# Clone
git clone https://github.com/praharsh-kumar/siem-log-generator.git
cd siem-log-generator

# Generate all logs
python generate_logs.py

# Convert formats
python convert_to_csv.py

Output Files

output/
β”œβ”€β”€ praharsh_siem_logs_3000.json      ← Full JSON (all fields)
β”œβ”€β”€ praharsh_siem_logs_3000.csv       ← Splunk / ELK import
β”œβ”€β”€ praharsh_siem_logs_wazuh.json     ← Wazuh-format (rule levels + agents)
└── praharsh_siem_logs_sentinel.json  ← Microsoft Sentinel KQL-ready

πŸ–₯️ SIEM Integration

Splunk

# Upload CSV via Splunk Web
Settings β†’ Add Data β†’ Upload β†’ praharsh_siem_logs_3000.csv

# Or monitor file
splunk add monitor /path/to/praharsh_siem_logs_3000.csv -sourcetype csv

Base SPL query:

source="praharsh_siem_logs_3000.csv" sourcetype="csv"
| head 20

Wazuh

# Copy to Wazuh manager
cp output/praharsh_siem_logs_wazuh.json /var/ossec/logs/alerts/

Microsoft Sentinel

Use the Sentinel KQL-ready JSON with Azure Log Analytics API:

import requests, json

with open("output/praharsh_siem_logs_sentinel.json") as f:
    logs = json.load(f)

# POST to Log Analytics workspace
headers = {"Authorization": "Bearer YOUR_TOKEN", "Content-Type": "application/json"}
requests.post("https://api.loganalytics.io/v1/workspaces/YOUR_WS/query",
              headers=headers, json={"logs": logs})

KQL query example:

praharsh_siem_logs_CL
| where Severity == "Critical"
| where MitreTechnique startswith "T1003"
| summarize count() by Computer, EventType
| sort by count_ desc

ELK / Logstash

input {
  file {
    path => "/path/to/praharsh_siem_logs_3000.json"
    codec => json
    start_position => "beginning"
  }
}
output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "praharsh-soc-lab-%{+yyyy.MM.dd}"
  }
}

πŸ“Š Splunk Dashboard

A complete Splunk dashboard is included in docs/SPLUNK_DASHBOARD_GUIDE.md.

Panels included:

  • Total Event Count
  • Security Events Over Time (by severity)
  • MITRE ATT&CK Technique Distribution
  • User Risk Scores
  • Failed Login Trends
  • C2 Communication Hotspots
  • Security Posture Score (Gauge)
  • Recent Malware Detections Table
  • Most Targeted Hosts

πŸ—ΊοΈ MITRE ATT&CK Coverage

Tactic Techniques
Initial Access T1566 (Phishing), T1078 (Valid Accounts)
Execution T1059 (PowerShell/CMD), T1218 (LOLBIN), T1047 (WMI)
Persistence T1053 (Sched Task), T1547 (Registry), T1543 (Service)
Privilege Escalation T1068, T1055 (Process Injection)
Defense Evasion T1070 (Log Clear), T1562 (Disable AV), T1218 (LOLBIN)
Credential Access T1003 (Mimikatz/LSASS), T1110 (Brute Force), T1558 (Kerberoasting)
Discovery T1046 (Nmap Port Scan)
Lateral Movement T1021 (RDP), T1570 (PsExec)
C2 T1071 (C2 Outbound), T1071.004 (DNS Tunnel)
Exfiltration T1048 (Data Transfer)
Impact T1486 (Ransomware)
Cloud T1098 (IAM Abuse), T1078.004 (Impossible Travel)

πŸ”§ Customization

Edit the config section in generate_logs.py:

# Update with your actual VM IPs
internal_ips = [
    "192.168.66.105",  # Your Windows VM
    "192.168.66.101",  # Your Splunk VM
    ...
]

attacker_ip = "192.168.66.104"  # Your Kali VM

# Add your own hostnames
hosts = ["WIN-PRAHARSH-01", "SPLUNK-VM-01", ...]

πŸ“ Project Structure

siem-log-generator/
β”œβ”€β”€ πŸ“œ generate_logs.py              # Main script β€” 3000+ events, 28 event types
β”œβ”€β”€ πŸ“œ convert_to_csv.py             # JSON to CSV converter
β”œβ”€β”€ πŸ“Š output/
β”‚   β”œβ”€β”€ praharsh_siem_logs_3000.json
β”‚   β”œβ”€β”€ praharsh_siem_logs_3000.csv
β”‚   β”œβ”€β”€ praharsh_siem_logs_wazuh.json
β”‚   └── praharsh_siem_logs_sentinel.json
β”œβ”€β”€ πŸ“– README.md
β”œβ”€β”€ πŸ“– USAGE.md
β”œβ”€β”€ πŸ“– docs/
β”‚   β”œβ”€β”€ SPLUNK_DASHBOARD_GUIDE.md
β”‚   └── ENTERPRISE_SOC_DASHBOARDS.md
└── πŸ“‹ requirements.txt

πŸ“œ License

MIT License β€” free to use, share, and modify.


Built for my Multi-SIEM SOC Lab πŸ›‘οΈ | Splunk + Wazuh + ELK + Sentinel

About

πŸ›‘οΈ Multi-SIEM log generator for SOC labs β€” Splunk, Wazuh, Sentinel, ELK | MITRE ATT&CK mapped | 3000+ realistic security events

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages