This sample, generated
The block below is 15 lines of Windows Security Event logs, produced by the real generator at seed 42 — deterministic, so this exact output regenerates anywhere. The live tool re-runs the identical engine on whatever source, seed, line count and anomalies you pick.
no anomalies injected — raise a slider to seed detectable patterns
Generated Windows Security Event logs
Real on-the-wire Windows Security Event logs — no real users, IPs, or secrets. Copy it into a fixture, feed it to a parser, or seed a SIEM demo.
With an anomaly injected: SSH brute-force
The same source, regenerated with a SSH brute-force injected at 30% intensity. 6 line sare tagged and highlighted below — A burst of failed logins from one source IP, then a success — the classic credential-stuffing signature. It is a documented, detectable pattern your SIEM rules should fire on — build the test data, then prove your detection works.
FAQ
- Are these real Windows Security events?
- No — the output is synthetic. It reproduces the Windows Security key=value event fields (EventID, TargetUserName, LogonType, IpAddress, Status, WorkstationName), but every account, host and address is fabricated. Safe for fixtures, demos and parser tests.
- Can I inject anomalies?
- Yes. An SSH brute-force / credential-stuffing burst maps cleanly onto repeated logon failures (4625) then a success — the slider appends that pattern and the injected lines are highlighted and badged so you can prove your account-attack rule fires.
- Is the output deterministic?
- Yes — fully seeded. The same seed and config always produce byte-identical Windows event lines, so a committed seed regenerates the exact same log anywhere.
Generate other log sources
- nginx access logs
- Apache access logs
- sshd / OpenSSH auth logs
- RFC 3164 (BSD) syslog
- RFC 5424 syslog
- FortiGate firewall logs
- Cisco ASA firewall logs
- JSON application logs
- Docker container logs
- Kubernetes (klog) logs
- AWS VPC Flow logs
Open the LogAnvil generator to tune the seed, line count, EPS, format and anomaly sliders — or build a parser with LogForge for a log you already have.
Generate your own Windows Security Event logs
Pick the seed, line count and EPS, inject the anomalies your rules should catch, and copy or download the result. Free, no account, nothing uploaded — generation runs entirely in your browser.
Open the LogAnvil generator →