Skip to content

Commit d27cc00

Browse files
Updated tests yaml file
1 parent d45fd74 commit d27cc00

File tree

1 file changed

+172
-9
lines changed

1 file changed

+172
-9
lines changed

openvpn/assets/logs/openvpn_tests.yaml

+172-9
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,27 @@ tests:
33
- sample: "<14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24
44
05:11:20 10.10.10.10:50540 [openvpn] Peer Connection Initiated with
55
[AF_INET]10.10.10.10:50546 (via [AF_INET]198.51.100.20%ens32)'"
6-
result: null
6+
result:
7+
custom:
8+
date: 1740373880000
9+
log_type: "Peer Connection Initiated"
10+
network:
11+
client:
12+
geoip: {}
13+
ip: "10.10.10.10"
14+
port: "50540"
15+
server_ip: "198.51.100.20"
16+
syslog:
17+
hostname: "openvpnas2"
18+
process_name: "openvpnas"
19+
syslog_message: "[-] [OVPN 2] OUT: '2025-02-24 05:11:20 10.10.10.10:50540 [openvpn] Peer Connection Initiated with [AF_INET]10.10.10.10:50546 (via [AF_INET]198.51.100.20%ens32)'"
20+
timestamp: 36220280000
21+
usr:
22+
name: "openvpn"
23+
message: "<14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24 05:11:20 10.10.10.10:50540 [openvpn] Peer Connection Initiated with [AF_INET]10.10.10.10:50546 (via [AF_INET]198.51.100.20%ens32)'"
24+
tags:
25+
- "source:LOGS_SOURCE"
26+
timestamp: 36220280000
727
- sample: "<14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] AUTH SUCCESS {'status':
828
0, 'user': 'openvpn', 'reason': 'local auth succeeded', 'auth method':
929
'local', 'proplist': {'prop_autogenerate': 'true', 'conn_group': 'test1',
@@ -13,33 +33,176 @@ tests:
1333
'pvt_google_auth_secret_locked': 'false'}, 'common_name': 'openvpn',
1434
'serial': '5735787958742102040', 'serial_list': []}
1535
cli='win'/'3.8connect1'/'OCWindows_3.4.0-3121'"
16-
result: null
36+
result:
37+
custom:
38+
auth_method: "local"
39+
client_connect_version: "3.4.0-3121"
40+
common_name: "openvpn"
41+
conn_group: "test1"
42+
log_type: "AUTH SUCCESS"
43+
os: "win"
44+
prop_autogenerate: "true"
45+
prop_autologin: "false"
46+
prop_deny: "false"
47+
prop_superuser: "true"
48+
pvt_google_auth_secret: "[redacted]"
49+
pvt_google_auth_secret_locked: "false"
50+
pvt_password_digest: "[redacted]"
51+
reason: "local auth succeeded"
52+
serial: "5735787958742102040"
53+
status: 0
54+
syslog:
55+
hostname: "openvpnas2"
56+
process_name: "openvpnas"
57+
syslog_message: "[-] AUTH SUCCESS {'status': 0, 'user': 'openvpn', 'reason': 'local auth succeeded', 'auth method': 'local', 'proplist': {'prop_autogenerate': 'true', 'conn_group': 'test1', 'prop_superuser': 'true', 'prop_autologin': 'false', 'prop_deny': 'false', 'type': 'user_compile', 'pvt_password_digest': '[redacted]', 'user_auth_type': 'local', 'pvt_google_auth_secret': '[redacted]', 'pvt_google_auth_secret_locked': 'false'}, 'common_name': 'openvpn', 'serial': '5735787958742102040', 'serial_list': []} cli='win'/'3.8connect1'/'OCWindows_3.4.0-3121'"
58+
timestamp: 36220280000
59+
type: "user_compile"
60+
user_auth_type: "local"
61+
usr:
62+
name: "openvpn"
63+
message: "<14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] AUTH SUCCESS {'status': 0, 'user': 'openvpn', 'reason': 'local auth succeeded', 'auth method': 'local', 'proplist': {'prop_autogenerate': 'true', 'conn_group': 'test1', 'prop_superuser': 'true', 'prop_autologin': 'false', 'prop_deny': 'false', 'type': 'user_compile', 'pvt_password_digest': '[redacted]', 'user_auth_type': 'local', 'pvt_google_auth_secret': '[redacted]', 'pvt_google_auth_secret_locked': 'false'}, 'common_name': 'openvpn', 'serial': '5735787958742102040', 'serial_list': []} cli='win'/'3.8connect1'/'OCWindows_3.4.0-3121'"
64+
tags:
65+
- "source:LOGS_SOURCE"
66+
timestamp: 36220280000
1767
- sample: "<14>Feb 24 05:11:13 openvpnas2 openvpnas: [-] VPN Auth Failed: 'local
1868
auth failed: password verification failed' [None]"
19-
result: null
69+
result:
70+
custom:
71+
log_type: "VPN Auth Failed"
72+
reason: "local auth failed: password verification failed"
73+
syslog:
74+
hostname: "openvpnas2"
75+
process_name: "openvpnas"
76+
syslog_message: "[-] VPN Auth Failed: 'local auth failed: password verification failed' [None]"
77+
timestamp: 36220273000
78+
message: "<14>Feb 24 05:11:13 openvpnas2 openvpnas: [-] VPN Auth Failed: 'local auth failed: password verification failed' [None]"
79+
tags:
80+
- "source:LOGS_SOURCE"
81+
timestamp: 36220273000
2082
- sample: "<14>Feb 24 05:12:14 openvpnas2 openvpnas: [-] [WEB] OUT:
2183
\"2025-02-24T05:12:14+0000 [stdout#info] Web login authentication failed:
2284
{'status': 1, 'user': 'openvpn', 'reason': 'local auth failed: password
2385
verification failed', 'auth method': 'local'}\""
24-
result: null
86+
result:
87+
custom:
88+
auth_method: "local"
89+
log_type: "Web login authentication failed"
90+
reason: "local auth failed: password verification failed"
91+
status: 1
92+
syslog:
93+
hostname: "openvpnas2"
94+
process_name: "openvpnas"
95+
syslog_message: "[-] [WEB] OUT: \"2025-02-24T05:12:14+0000 [stdout#info] Web login authentication failed: {'status': 1, 'user': 'openvpn', 'reason': 'local auth failed: password verification failed', 'auth method': 'local'}\""
96+
timestamp: 36220334000
97+
usr:
98+
name: "openvpn"
99+
message: "<14>Feb 24 05:12:14 openvpnas2 openvpnas: [-] [WEB] OUT: \"2025-02-24T05:12:14+0000 [stdout#info] Web login authentication failed: {'status': 1, 'user': 'openvpn', 'reason': 'local auth failed: password verification failed', 'auth method': 'local'}\""
100+
tags:
101+
- "source:LOGS_SOURCE"
102+
timestamp: 36220334000
25103
- sample: "<14>Feb 24 04:50:22 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24
26104
04:50:22 openvpn/10.10.10.10:51820 MULTI: primary virtual IP for
27105
openvpn/10.10.10.10:51820: 10.10.10.10'"
28-
result: null
106+
result:
107+
custom:
108+
client_mode: "MULTI"
109+
date: 1740372622000
110+
log_type: "Assigning virtual IP"
111+
network:
112+
client:
113+
geoip: {}
114+
ip: "10.10.10.10"
115+
port: "51820"
116+
syslog:
117+
hostname: "openvpnas2"
118+
process_name: "openvpnas"
119+
syslog_message: "[-] [OVPN 2] OUT: '2025-02-24 04:50:22 openvpn/10.10.10.10:51820 MULTI: primary virtual IP for openvpn/10.10.10.10:51820: 10.10.10.10'"
120+
timestamp: 36219022000
121+
usr:
122+
name: "openvpn"
123+
virtual_ip: "10.10.10.10"
124+
message: "<14>Feb 24 04:50:22 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24 04:50:22 openvpn/10.10.10.10:51820 MULTI: primary virtual IP for openvpn/10.10.10.10:51820: 10.10.10.10'"
125+
tags:
126+
- "source:LOGS_SOURCE"
127+
timestamp: 36219022000
29128
- sample: "<14>Feb 24 08:43:52 openvpnas2 openvpnas: [-] AUTH ERROR: DENY: user in
30129
deny list. user=test5"
31-
result: null
130+
result:
131+
custom:
132+
log_type: "AUTH ERROR"
133+
reason: "DENY: user in deny list."
134+
syslog:
135+
hostname: "openvpnas2"
136+
process_name: "openvpnas"
137+
syslog_message: "[-] AUTH ERROR: DENY: user in deny list. user=test5"
138+
timestamp: 36233032000
139+
usr:
140+
name: "test5"
141+
message: "<14>Feb 24 08:43:52 openvpnas2 openvpnas: [-] AUTH ERROR: DENY: user in deny list. user=test5"
142+
tags:
143+
- "source:LOGS_SOURCE"
144+
timestamp: 36233032000
32145
- sample: "<14>Feb 24 08:41:52 openvpnas2 openvpnas: [-] AUTH ERROR: local auth
33146
failed: no stored password digest found in authcred attributes. user=test"
34-
result: null
147+
result:
148+
custom:
149+
log_type: "AUTH ERROR"
150+
reason: "local auth failed: no stored password digest found in authcred attributes."
151+
syslog:
152+
hostname: "openvpnas2"
153+
process_name: "openvpnas"
154+
syslog_message: "[-] AUTH ERROR: local auth failed: no stored password digest found in authcred attributes. user=test"
155+
timestamp: 36232912000
156+
usr:
157+
name: "test"
158+
message: "<14>Feb 24 08:41:52 openvpnas2 openvpnas: [-] AUTH ERROR: local auth failed: no stored password digest found in authcred attributes. user=test"
159+
tags:
160+
- "source:LOGS_SOURCE"
161+
timestamp: 36232912000
35162
- sample: "<14>Feb 24 05:11:19 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24
36163
05:11:19 172.20.4.202:58075 SIGTERM[soft,delayed-exit] received,
37164
client-instance exiting'"
38-
result: null
165+
result:
166+
custom:
167+
date: 1740373879000
168+
log_type: "client-instance exiting"
169+
network:
170+
client:
171+
geoip: {}
172+
ip: "172.20.4.202"
173+
port: "58075"
174+
signal_details: "SIGTERM[soft,delayed-exit]"
175+
syslog:
176+
hostname: "openvpnas2"
177+
process_name: "openvpnas"
178+
syslog_message: "[-] [OVPN 2] OUT: '2025-02-24 05:11:19 172.20.4.202:58075 SIGTERM[soft,delayed-exit] received, client-instance exiting'"
179+
termination_signal: "soft,delayed-exit"
180+
timestamp: 36220279000
181+
message: "<14>Feb 24 05:11:19 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24 05:11:19 172.20.4.202:58075 SIGTERM[soft,delayed-exit] received, client-instance exiting'"
182+
tags:
183+
- "source:LOGS_SOURCE"
184+
timestamp: 36220279000
39185
- sample: "<14>Mar 11 12:59:46 openvpnas2 openvpnas: [-] [WEB] OUT:
40186
'2025-03-11T12:59:46+0000 [stdout#info] Web login authentication failed:
41187
{\\'status\\': 2, \\'user\\': \\'abc\\', \\'reason\\': \"Cannot connect to
42188
LDAP server ldap://10.10.10.10: socket connection error while opening:
43189
[Errno 113] No route to host (facility=\\'initialize [10.10.10.10]\\')\",
44190
\\'auth method\\': \\'ldap\\'}'"
45-
result: null
191+
result:
192+
result:
193+
custom:
194+
auth_method: "ldap"
195+
log_type: "Web login authentication failed"
196+
reason: "Cannot connect to LDAP server ldap://10.10.10.10: socket connection error while opening: [Errno 113] No route to host (facility=\\'initialize [10.10.10.10]\\')"
197+
status: 2
198+
syslog:
199+
hostname: "openvpnas2"
200+
process_name: "openvpnas"
201+
syslog_message: "[-] [WEB] OUT: '2025-03-11T12:59:46+0000 [stdout#info] Web login authentication failed: {\\'status\\': 2, \\'user\\': \\'abc\\', \\'reason\\': \"Cannot connect to LDAP server ldap://10.10.10.10: socket connection error while opening: [Errno 113] No route to host (facility=\\'initialize [10.10.10.10]\\')\", \\'auth method\\': \\'ldap\\'}'"
202+
timestamp: 37544386000
203+
usr:
204+
name: "abc"
205+
message: "<14>Mar 11 12:59:46 openvpnas2 openvpnas: [-] [WEB] OUT: '2025-03-11T12:59:46+0000 [stdout#info] Web login authentication failed: {\\'status\\': 2, \\'user\\': \\'abc\\', \\'reason\\': \"Cannot connect to LDAP server ldap://10.10.10.10: socket connection error while opening: [Errno 113] No route to host (facility=\\'initialize [10.10.10.10]\\')\", \\'auth method\\': \\'ldap\\'}'"
206+
tags:
207+
- "source:LOGS_SOURCE"
208+
timestamp: 37544386000

0 commit comments

Comments
 (0)