Overview
S4 LogForge generates security logs that are field-faithful to real devices and SIEM schemas - for when you need production-like data for a SIEM project but cannot use production logs.
WHAT YOU GET
-
13 output formats, each verified end-to-end against real parsers (Elasticsearch ingest pipelines, Elastic integration pipelines, Logstash grok / kv / xml / CEF codec): RFC 3164 and RFC 5424 syslog; CEF (ArcSight-style); LEEF 2.0 (QRadar-style); PAN-OS 10.2 CSV (TRAFFIC/THREAT/SYSTEM); Elastic Common Schema (ECS) 8.11 JSON; XDR telemetry JSON; Windows Event Log XML (Security/Sysmon) and Winlogbeat-shaped JSON; AWS CloudTrail and VPC Flow Logs; Zeek; and Suricata EVE.
-
Correlated attack scenarios - brute force to lateral movement, malware beaconing, port scans, insider data exfil, and cloud credential abuse - every event tagged with MITRE ATT&CK technique IDs. Inject them into baseline noise at known times to measure detection and false-positive rates with known ground truth.
-
Custom scenarios: author your own correlated attack sequences in a simple TOML DSL - phases, timing, entity bindings, and ATT&CK tags - and inject them like the built-ins.
-
Entity consistency: hosts keep their IPs and hostnames, users log in from their usual workstations, GeoIP and cloud identities stay coherent across the entire stream.
-
Realistic shape: business-hours diurnal rate curves, log-normal session sizes, benign auth-failure noise, IDS false positives, DNS lookups and C2 beaconing.
-
Deterministic: same seed and config produce byte-identical output, so any test is exactly reproducible.
-
Throughput: single-core generation sustains 188k to 1.6M events/sec depending on format; a 30-day PoC backfill generates in minutes.
-
Outputs: stdout, rotating files, syslog forward (UDP / TCP / TLS), Elasticsearch and OpenSearch bulk, and Splunk HEC (with native event-time so backfill lands at the right time).
-
Capacity estimator answers "N hosts at X EPS = how many GB/day per format?" before you size a cluster. Prometheus metrics endpoint for long-running streams.
WHY NOT THE ALTERNATIVES
Generic fake-log tools emit Apache-style noise with no security-product fields. Template-driven event generators ship empty - the content is your problem. Static datasets cannot be re-rated, re-dated, or re-formatted. S4 LogForge ships the content: field mappings modeled on real devices and schemas, kept current.
TYPICAL USES
- SIEM PoC: 30-day backfill of 200 hosts in minutes, then realtime drip
- Detection engineering: generate exactly the log sequence a rule should fire on, tagged with ATT&CK techniques
- Dashboards and capacity sizing with realistic volume and shape
- Ingest load testing at controlled EPS
A free Community edition (separate listing) covers syslog and CEF at a capped rate.
Highlights
- 13 parser-faithful formats - syslog 3164/5424, CEF, LEEF, PAN-OS CSV, ECS JSON, Windows Event/Winlogbeat, CloudTrail, VPC Flow, Zeek, Suricata, XDR telemetry - each verified against real parsers, not just 'looks like a log'.
- Correlated, MITRE ATT&CK-tagged attack scenarios injected into realistic baseline noise, plus a TOML DSL to author your own - measure detection and false-positive rates against known ground truth.
- Deterministic and rate-controlled: same seed reproduces byte-identical data; sustain 188k-1.6M events/sec, backfill 30 days in minutes, or stream a realtime diurnal curve to file, syslog, Elasticsearch, or Splunk HEC.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
t3.medium Recommended | $0.15 |
m5.2xlarge | $0.15 |
t3.large | $0.15 |
m5.xlarge | $0.15 |
t3.2xlarge | $0.15 |
c5.large | $0.15 |
c5.xlarge | $0.15 |
c5.2xlarge | $0.15 |
t3.small | $0.15 |
m5.large | $0.15 |
Vendor refund policy
Hourly software charges are generally non-refundable. For billing issues, contact seller support within 30 days and we will work with you and AWS Marketplace to resolve them.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial GA release. 13 SIEM log formats, 5 MITRE ATT&CK-tagged attack scenarios, a custom-scenario TOML DSL, and outputs to file, syslog, Elasticsearch/OpenSearch, and Splunk HEC.
Additional details
Usage instructions
After launch, SSH in as ec2-user. Run: logforge run --config /opt/logforge/examples/poc.toml --sink stdout | head to see sample output. 'logforge formats' lists the 13 supported formats; 'logforge scenarios' lists the built-in attack scenarios; 'logforge estimate' sizes GB/day. Full quickstart in /opt/logforge/README.txt. Generate to stdout, rotating files, syslog (UDP/TCP/TLS), Elasticsearch/OpenSearch bulk, or Splunk HEC; backfill historical data or stream in realtime.
Support
Vendor support
Support is provided by abyo software G.K. by email at aws-support@abyo.net for installation, configuration, output-format, and licensing questions, typically within two business days. The AMI also ships an in-instance README at /opt/logforge with quickstart, examples, and troubleshooting.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

