3
3
- sample : " <14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24
4
4
05:11:20 10.10.10.10:50540 [openvpn] Peer Connection Initiated with
5
5
[AF_INET]10.10.10.10:50546 (via [AF_INET]198.51.100.20%ens32)'"
6
- result : null
6
+ result :
7
+ custom :
8
+ date : 1740373880000
9
+ log_type : " Peer Connection Initiated"
10
+ network :
11
+ client :
12
+ geoip : {}
13
+ ip : " 10.10.10.10"
14
+ port : " 50540"
15
+ server_ip : " 198.51.100.20"
16
+ syslog :
17
+ hostname : " openvpnas2"
18
+ process_name : " openvpnas"
19
+ syslog_message : " [-] [OVPN 2] OUT: '2025-02-24 05:11:20 10.10.10.10:50540 [openvpn] Peer Connection Initiated with [AF_INET]10.10.10.10:50546 (via [AF_INET]198.51.100.20%ens32)'"
20
+ timestamp : 36220280000
21
+ usr :
22
+ name : " openvpn"
23
+ message : " <14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24 05:11:20 10.10.10.10:50540 [openvpn] Peer Connection Initiated with [AF_INET]10.10.10.10:50546 (via [AF_INET]198.51.100.20%ens32)'"
24
+ tags :
25
+ - " source:LOGS_SOURCE"
26
+ timestamp : 36220280000
7
27
- sample : " <14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] AUTH SUCCESS {'status':
8
28
0, 'user': 'openvpn', 'reason': 'local auth succeeded', 'auth method':
9
29
'local', 'proplist': {'prop_autogenerate': 'true', 'conn_group': 'test1',
@@ -13,33 +33,176 @@ tests:
13
33
'pvt_google_auth_secret_locked': 'false'}, 'common_name': 'openvpn',
14
34
'serial': '5735787958742102040', 'serial_list': []}
15
35
cli='win'/'3.8connect1'/'OCWindows_3.4.0-3121'"
16
- result : null
36
+ result :
37
+ custom :
38
+ auth_method : " local"
39
+ client_connect_version : " 3.4.0-3121"
40
+ common_name : " openvpn"
41
+ conn_group : " test1"
42
+ log_type : " AUTH SUCCESS"
43
+ os : " win"
44
+ prop_autogenerate : " true"
45
+ prop_autologin : " false"
46
+ prop_deny : " false"
47
+ prop_superuser : " true"
48
+ pvt_google_auth_secret : " [redacted]"
49
+ pvt_google_auth_secret_locked : " false"
50
+ pvt_password_digest : " [redacted]"
51
+ reason : " local auth succeeded"
52
+ serial : " 5735787958742102040"
53
+ status : 0
54
+ syslog :
55
+ hostname : " openvpnas2"
56
+ process_name : " openvpnas"
57
+ syslog_message : " [-] AUTH SUCCESS {'status': 0, 'user': 'openvpn', 'reason': 'local auth succeeded', 'auth method': 'local', 'proplist': {'prop_autogenerate': 'true', 'conn_group': 'test1', 'prop_superuser': 'true', 'prop_autologin': 'false', 'prop_deny': 'false', 'type': 'user_compile', 'pvt_password_digest': '[redacted]', 'user_auth_type': 'local', 'pvt_google_auth_secret': '[redacted]', 'pvt_google_auth_secret_locked': 'false'}, 'common_name': 'openvpn', 'serial': '5735787958742102040', 'serial_list': []} cli='win'/'3.8connect1'/'OCWindows_3.4.0-3121'"
58
+ timestamp : 36220280000
59
+ type : " user_compile"
60
+ user_auth_type : " local"
61
+ usr :
62
+ name : " openvpn"
63
+ message : " <14>Feb 24 05:11:20 openvpnas2 openvpnas: [-] AUTH SUCCESS {'status': 0, 'user': 'openvpn', 'reason': 'local auth succeeded', 'auth method': 'local', 'proplist': {'prop_autogenerate': 'true', 'conn_group': 'test1', 'prop_superuser': 'true', 'prop_autologin': 'false', 'prop_deny': 'false', 'type': 'user_compile', 'pvt_password_digest': '[redacted]', 'user_auth_type': 'local', 'pvt_google_auth_secret': '[redacted]', 'pvt_google_auth_secret_locked': 'false'}, 'common_name': 'openvpn', 'serial': '5735787958742102040', 'serial_list': []} cli='win'/'3.8connect1'/'OCWindows_3.4.0-3121'"
64
+ tags :
65
+ - " source:LOGS_SOURCE"
66
+ timestamp : 36220280000
17
67
- sample : " <14>Feb 24 05:11:13 openvpnas2 openvpnas: [-] VPN Auth Failed: 'local
18
68
auth failed: password verification failed' [None]"
19
- result : null
69
+ result :
70
+ custom :
71
+ log_type : " VPN Auth Failed"
72
+ reason : " local auth failed: password verification failed"
73
+ syslog :
74
+ hostname : " openvpnas2"
75
+ process_name : " openvpnas"
76
+ syslog_message : " [-] VPN Auth Failed: 'local auth failed: password verification failed' [None]"
77
+ timestamp : 36220273000
78
+ message : " <14>Feb 24 05:11:13 openvpnas2 openvpnas: [-] VPN Auth Failed: 'local auth failed: password verification failed' [None]"
79
+ tags :
80
+ - " source:LOGS_SOURCE"
81
+ timestamp : 36220273000
20
82
- sample : " <14>Feb 24 05:12:14 openvpnas2 openvpnas: [-] [WEB] OUT:
21
83
\" 2025-02-24T05:12:14+0000 [stdout#info] Web login authentication failed:
22
84
{'status': 1, 'user': 'openvpn', 'reason': 'local auth failed: password
23
85
verification failed', 'auth method': 'local'}\" "
24
- result : null
86
+ result :
87
+ custom :
88
+ auth_method : " local"
89
+ log_type : " Web login authentication failed"
90
+ reason : " local auth failed: password verification failed"
91
+ status : 1
92
+ syslog :
93
+ hostname : " openvpnas2"
94
+ process_name : " openvpnas"
95
+ syslog_message : " [-] [WEB] OUT: \" 2025-02-24T05:12:14+0000 [stdout#info] Web login authentication failed: {'status': 1, 'user': 'openvpn', 'reason': 'local auth failed: password verification failed', 'auth method': 'local'}\" "
96
+ timestamp : 36220334000
97
+ usr :
98
+ name : " openvpn"
99
+ message : " <14>Feb 24 05:12:14 openvpnas2 openvpnas: [-] [WEB] OUT: \" 2025-02-24T05:12:14+0000 [stdout#info] Web login authentication failed: {'status': 1, 'user': 'openvpn', 'reason': 'local auth failed: password verification failed', 'auth method': 'local'}\" "
100
+ tags :
101
+ - " source:LOGS_SOURCE"
102
+ timestamp : 36220334000
25
103
- sample : " <14>Feb 24 04:50:22 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24
26
104
04:50:22 openvpn/10.10.10.10:51820 MULTI: primary virtual IP for
27
105
openvpn/10.10.10.10:51820: 10.10.10.10'"
28
- result : null
106
+ result :
107
+ custom :
108
+ client_mode : " MULTI"
109
+ date : 1740372622000
110
+ log_type : " Assigning virtual IP"
111
+ network :
112
+ client :
113
+ geoip : {}
114
+ ip : " 10.10.10.10"
115
+ port : " 51820"
116
+ syslog :
117
+ hostname : " openvpnas2"
118
+ process_name : " openvpnas"
119
+ syslog_message : " [-] [OVPN 2] OUT: '2025-02-24 04:50:22 openvpn/10.10.10.10:51820 MULTI: primary virtual IP for openvpn/10.10.10.10:51820: 10.10.10.10'"
120
+ timestamp : 36219022000
121
+ usr :
122
+ name : " openvpn"
123
+ virtual_ip : " 10.10.10.10"
124
+ message : " <14>Feb 24 04:50:22 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24 04:50:22 openvpn/10.10.10.10:51820 MULTI: primary virtual IP for openvpn/10.10.10.10:51820: 10.10.10.10'"
125
+ tags :
126
+ - " source:LOGS_SOURCE"
127
+ timestamp : 36219022000
29
128
- sample : " <14>Feb 24 08:43:52 openvpnas2 openvpnas: [-] AUTH ERROR: DENY: user in
30
129
deny list. user=test5"
31
- result : null
130
+ result :
131
+ custom :
132
+ log_type : " AUTH ERROR"
133
+ reason : " DENY: user in deny list."
134
+ syslog :
135
+ hostname : " openvpnas2"
136
+ process_name : " openvpnas"
137
+ syslog_message : " [-] AUTH ERROR: DENY: user in deny list. user=test5"
138
+ timestamp : 36233032000
139
+ usr :
140
+ name : " test5"
141
+ message : " <14>Feb 24 08:43:52 openvpnas2 openvpnas: [-] AUTH ERROR: DENY: user in deny list. user=test5"
142
+ tags :
143
+ - " source:LOGS_SOURCE"
144
+ timestamp : 36233032000
32
145
- sample : " <14>Feb 24 08:41:52 openvpnas2 openvpnas: [-] AUTH ERROR: local auth
33
146
failed: no stored password digest found in authcred attributes. user=test"
34
- result : null
147
+ result :
148
+ custom :
149
+ log_type : " AUTH ERROR"
150
+ reason : " local auth failed: no stored password digest found in authcred attributes."
151
+ syslog :
152
+ hostname : " openvpnas2"
153
+ process_name : " openvpnas"
154
+ syslog_message : " [-] AUTH ERROR: local auth failed: no stored password digest found in authcred attributes. user=test"
155
+ timestamp : 36232912000
156
+ usr :
157
+ name : " test"
158
+ message : " <14>Feb 24 08:41:52 openvpnas2 openvpnas: [-] AUTH ERROR: local auth failed: no stored password digest found in authcred attributes. user=test"
159
+ tags :
160
+ - " source:LOGS_SOURCE"
161
+ timestamp : 36232912000
35
162
- sample : " <14>Feb 24 05:11:19 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24
36
163
05:11:19 172.20.4.202:58075 SIGTERM[soft,delayed-exit] received,
37
164
client-instance exiting'"
38
- result : null
165
+ result :
166
+ custom :
167
+ date : 1740373879000
168
+ log_type : " client-instance exiting"
169
+ network :
170
+ client :
171
+ geoip : {}
172
+ ip : " 172.20.4.202"
173
+ port : " 58075"
174
+ signal_details : " SIGTERM[soft,delayed-exit]"
175
+ syslog :
176
+ hostname : " openvpnas2"
177
+ process_name : " openvpnas"
178
+ syslog_message : " [-] [OVPN 2] OUT: '2025-02-24 05:11:19 172.20.4.202:58075 SIGTERM[soft,delayed-exit] received, client-instance exiting'"
179
+ termination_signal : " soft,delayed-exit"
180
+ timestamp : 36220279000
181
+ message : " <14>Feb 24 05:11:19 openvpnas2 openvpnas: [-] [OVPN 2] OUT: '2025-02-24 05:11:19 172.20.4.202:58075 SIGTERM[soft,delayed-exit] received, client-instance exiting'"
182
+ tags :
183
+ - " source:LOGS_SOURCE"
184
+ timestamp : 36220279000
39
185
- sample : " <14>Mar 11 12:59:46 openvpnas2 openvpnas: [-] [WEB] OUT:
40
186
'2025-03-11T12:59:46+0000 [stdout#info] Web login authentication failed:
41
187
{\\ 'status\\ ': 2, \\ 'user\\ ': \\ 'abc\\ ', \\ 'reason\\ ': \" Cannot connect to
42
188
LDAP server ldap://10.10.10.10: socket connection error while opening:
43
189
[Errno 113] No route to host (facility=\\ 'initialize [10.10.10.10]\\ ')\" ,
44
190
\\ 'auth method\\ ': \\ 'ldap\\ '}'"
45
- result : null
191
+ result :
192
+ result :
193
+ custom :
194
+ auth_method : " ldap"
195
+ log_type : " Web login authentication failed"
196
+ reason : " Cannot connect to LDAP server ldap://10.10.10.10: socket connection error while opening: [Errno 113] No route to host (facility=\\ 'initialize [10.10.10.10]\\ ')"
197
+ status : 2
198
+ syslog :
199
+ hostname : " openvpnas2"
200
+ process_name : " openvpnas"
201
+ syslog_message : " [-] [WEB] OUT: '2025-03-11T12:59:46+0000 [stdout#info] Web login authentication failed: {\\ 'status\\ ': 2, \\ 'user\\ ': \\ 'abc\\ ', \\ 'reason\\ ': \" Cannot connect to LDAP server ldap://10.10.10.10: socket connection error while opening: [Errno 113] No route to host (facility=\\ 'initialize [10.10.10.10]\\ ')\" , \\ 'auth method\\ ': \\ 'ldap\\ '}'"
202
+ timestamp : 37544386000
203
+ usr :
204
+ name : " abc"
205
+ message : " <14>Mar 11 12:59:46 openvpnas2 openvpnas: [-] [WEB] OUT: '2025-03-11T12:59:46+0000 [stdout#info] Web login authentication failed: {\\ 'status\\ ': 2, \\ 'user\\ ': \\ 'abc\\ ', \\ 'reason\\ ': \" Cannot connect to LDAP server ldap://10.10.10.10: socket connection error while opening: [Errno 113] No route to host (facility=\\ 'initialize [10.10.10.10]\\ ')\" , \\ 'auth method\\ ': \\ 'ldap\\ '}'"
206
+ tags :
207
+ - " source:LOGS_SOURCE"
208
+ timestamp : 37544386000
0 commit comments