Skip to main content

Simulation Placeholders

A template is a block of text whose {{name}} slots are filled in afresh for every record it produces. Each slot is a placeholder: a typed instruction such as "an address from this range", "one of these three words", "a timestamp in syslog format".

Templates are written in two places, and both use the placeholders described here:

Everything on this page is the same on both surfaces.

Writing a Template​

Every non-empty line of a template is one candidate record. A template of four lines produces four different records, cycling through them in order or picking at random — see Device Simulation for the Line order setting.

<134>{{ts}} fw-edge-01 vmfw: action=allow src={{src_ip}}:{{src_port}} dst={{dst_ip}}:443 user={{username}}
<134>{{ts}} fw-edge-01 vmfw: action=deny src={{src_ip}}:{{src_port}} dst={{dst_ip}}:22 user={{username}}

Two rules decide what a {{name}} does, and both catch people out.

Any Type Name Works on Its Own​

A {{name}} that is itself the name of a placeholder type needs no definition. Writing {{ip}}, {{email}} or {{http_status}} produces an address, an e-mail address and an HTTP status code using that type's defaults, with nothing added to the Placeholders list.

The one exception is {{choice}}. A choice has no values to choose from until you declare them, so a bare {{choice}} is rejected like any other name that was never defined.

Every name that is not a type name has to be declared. {{src_ip}} is not a type, so it needs a Placeholders entry named src_ip — and a typo such as {{src_pi}} is refused when you save, rather than appearing in the output as the literal text {{src_pi}}.

Declaring a placeholder under a type's own name overrides that type's defaults. An entry named ip with a range of 203.0.113.0/24 makes every bare {{ip}} in the template draw from that range instead.

A Placeholder Is Filled Once per Record​

Each name is evaluated once per record and the same value is used everywhere it appears on that line. Writing {{src_ip}} twice yields the same address both times, which is what lets a record mention the same host in two fields and stay consistent.

Two different values on one record therefore need two names:

connection from {{src_ip}} to {{dst_ip}}

This applies per record, not for the life of the device: the next record draws fresh values for both.

Placeholder Types​

Twenty types are available. The Type dropdown in the placeholder editor shows the label; the name in the second column is what you write as {{name}} and what appears in a device's configuration.

LabelTypeOptions it readsProduces
IP addressiprange, uniqueAn IPv4 address from the range
Integerintmin, max, range, uniqueA whole number
Portportmin, max, range, uniqueA port number
Decimal numberfloatmin, max, precisionA decimal number
One of a listchoicevalues, weightsOne of the values you list
TimestamptimestampformatThe current time, formatted
UUIDuuid-A version 4 UUID
Hex stringhexlengthLower-case hexadecimal digits
Random stringstringlengthLetters and digits
MAC addressmac-A locally administered unicast MAC address
Sequencesequencestart, stepA counter that advances every record
User nameusername-A user name from a built-in list
Host namehostname-A host name from a built-in list
Domaindomain-A domain name from a built-in list
E-mail addressemail-An address from a built-in list
User agentuser_agent-A browser or client user-agent string
HTTP methodhttp_method-GET, POST, PUT, DELETE, HEAD, OPTIONS or PATCH
HTTP statushttp_status-A status code such as 200, 404 or 503
URL pathurl_path-A request path from a built-in list
Country codecountry-A two-letter country code

The placeholder editor shows only the options the selected type reads. An option a type does not read is ignored.

A few alternative spellings are accepted wherever a type name is: ipv4, ipaddress and ip_address for ip; integer and number for int; enum, oneof and list for choice; time, datetime and date for timestamp; guid for uuid; seq and counter for sequence; useragent for user_agent; user and account for username; and host for hostname.

Options​

OptionLabelApplies toDefaultDescription
rangeRangeip, int, port-On an ip, first and last address as 203.0.113.10-203.0.113.250, or a CIDR block such as 203.0.113.0/24; a single address is also accepted. Required unless the placeholder is a bare {{ip}}, which uses 10.0.0.0-10.255.255.255. IPv4 only. On an int or a port, min-max as a single value — a shorthand for the two fields below. A min or a max set alongside it replaces that one bound and leaves the other as the range gave it; a bound left unset keeps the range's. The placeholder editor offers Range on IP addresses only, so a range on a number is something you will meet in a sample rather than type
minMinimumint, port, float0 for int, 1 for port, 0 for floatLowest value, inclusive
maxMaximumint, port, float2147483647 for int, 65535 for port, 1 for floatHighest value, inclusive. A maximum below the minimum is refused
precisionDecimal placesfloat2Digits after the decimal point, at most 9
valuesValueschoice-Comma-separated list to pick from. At least one, at most 1000
weightsWeights (Optional)choice-One positive weight per value, in the same order. Leaving it empty picks evenly. A weight that is missing, zero or negative is refused rather than ignored
formatFormattimestamprfc3339See Timestamp Formats
lengthLengthhex, string16 for hex, 8 for stringNumber of characters, between 1 and 1024
startStartsequence1First value of the sequence
stepStepsequence1Added after every record
uniqueUniqueip, int, portOffWalk the whole range without repeating a value before starting over. The range may span at most about a trillion values, which covers any IPv4 range

A placeholder name may contain letters, digits and underscores, and may not start with a digit. Names are case-sensitive and each has to be unique within the template.

Built-in Value Lists​

username, hostname, domain, email, user_agent, http_method, http_status, url_path and country draw from lists that ship with the product and take no options. The lists are weighted towards what real traffic looks like rather than picking evenly, so GET is far more common than DELETE and 200 far more common than 503. Use choice instead when you need your own values.

Timestamp Formats​

A timestamp placeholder renders the moment the record is generated. Format accepts one of the names below, or a Go time layout written against the reference time Mon Jan 2 15:04:05 MST 2006.

FormatRenders as
rfc33392026-09-19T14:32:07Z
rfc3339nano2026-09-19T14:32:07.123456789Z
iso86012026-09-19T14:32:07.123Z
syslogSep 19 14:32:07
cefSep 19 2026 14:32:07
http19/Sep/2026:14:32:07 +0000
windows2026-09-19 14:32:07
epoch1789828327
epoch_ms1789828327123
epoch_ns1789828327123456789
Choosing the wrong epoch scale does not fail

The three epoch formats differ only in scale: epoch counts seconds, epoch_ms milliseconds and epoch_ns nanoseconds. A record carrying a value on the wrong scale is still a valid number, so nothing is rejected — the records simply arrive dated near 1970, or centuries into the future, and the mistake only shows up once you look at the timestamps downstream. Match the scale to what the receiving system expects.

The Format field's own hint lists nine of these names; epoch_ns is accepted as well, and so are the spellings unix, unix_ms, epochms, unix_ns and epochns.

Timestamps always render in UTC.

Limits​

LimitValue
Placeholders per template64
Lines per template1000
Characters per template line65536
Values in one choice1000

A template that exceeds any of these is refused when you save it.

Errors​

A template and its placeholders are checked when you save, so a problem is reported there rather than when the device starts.

MessageCause
simulation: template has no non-empty linesThe template is empty or contains only blank lines
simulation: template has too many linesMore than 1000 non-empty lines
simulation: template line is too longA single line longer than 65536 characters
simulation: too many placeholdersMore than 64 placeholders in play, declared and bare types together
simulation: unknown placeholderThe template references a name that is neither declared nor a type name. Every offending name is listed
simulation: invalid placeholder nameA name using characters other than letters, digits and underscores, or starting with a digit
simulation: duplicate placeholder nameTwo entries share a name
simulation: invalid placeholder typeA type that does not exist, or a placeholder saved with no type
simulation: invalid rangeA range that cannot be read, an end before its start, an IPv6 address, a maximum below its minimum, or a choice with more than 1000 values
simulation: choice needs at least one valueA choice with an empty Values list
simulation: weights must be positive and match valuesThe weights are a different length to the values, or one of them is not a positive number
simulation: range too large for unique valuesUnique on a range spanning more than about a trillion values
simulation: length out of rangeA hex or string length outside 1 to 1024