SurePassID Compliance Manager Datasheet: HIPAA and CMMC 2.0
SurePassID Authentication Server
Multiple Event Sources
Last Updated: July 2025
The compliance system supports ingesting authentication events from
multiple sources simultaneously. When multiple sources are enabled,
events are fetched in parallel and merged chronologically using
AggregateEventSource.
Configuration
Enable multiple sources in the EventSources section of
appsettings.json:
{
"EventSources": {
"SurePassID": { "Enabled": true },
"WindowsEventLog": { "Enabled": true },
"JsonFile": {
"Enabled": false,
"DirectoryPath": "./Events",
"FilePattern": "*.json"
},
"Syslog": { "Enabled": false }
}
}Each source has its own top-level configuration section for detailed settings.
Available Sources
| Source | Config Key | Top-Level Section | Description |
|---|---|---|---|
| SurePassID REST API | EventSources:SurePassID |
SurePassID |
Real-time MFA events from SurePassID server |
| Windows Event Log | EventSources:WindowsEventLog |
WindowsEventLog |
AD login events (Security log 4624, 4625, etc.) |
| JSON Files | EventSources:JsonFile |
(inline) | SIEM exports (Splunk, Sentinel) |
| Syslog | EventSources:Syslog |
(inline) | RFC 5424/3164/CEF log files |
| Entra ID | EventSources:EntraIdJson /
EntraIdGraph |
EntraId |
Azure AD sign-in logs |
Common Multi-Source Combinations
SurePassID + Windows Event Log (Recommended for AD environments)
Correlates MFA events from SurePassID with AD logon events from the Security log:
{
"EventSources": {
"SurePassID": { "Enabled": true },
"WindowsEventLog": { "Enabled": true }
},
"SurePassID": {
"Endpoint": "https://mfa.company.com/api/mfa/v1",
"ApiKeyId": "compliance-api",
"ApiKey": "your-api-key",
"IgnoreSyncStatus": true,
"PreferJsonBulkFormat": true
},
"WindowsEventLog": {
"LogName": "Security",
"ComputerNames": ["dc01.company.com"],
"IncludeSuccessfulLogons": true,
"IncludeFailedLogons": true,
"ExcludeMachineAccounts": true,
"ExcludeSystemAccounts": true,
"MaxEventsPerQuery": 10000
},
"ActiveDirectory": {
"Server": "dc01.company.com",
"BaseDn": "DC=company,DC=com",
"UseIntegratedAuth": true
}
}SurePassID + JSON File Import
Supplement real-time MFA data with historical SIEM exports:
{
"EventSources": {
"SurePassID": { "Enabled": true },
"JsonFile": {
"Enabled": true,
"DirectoryPath": "C:\\Logs\\SiemExports",
"FilePattern": "*.json"
}
}
}How It Works
- Registration: At startup, the CLI, service, or MCP
server registers an
IAuthEventSourcefor each enabled source. - Aggregation: When more than one source is
registered, an
AggregateEventSourcewraps them. - Parallel Fetch:
AggregateEventSource.FetchAsync()calls each source concurrently. - Merge: Results are combined into a single list sorted by event timestamp (UTC-normalized).
- Fault Tolerance: If one source fails, the others still return their events. Failures are logged as warnings.
- MFA Coverage: When both Windows Event Log and
SurePassID sources are active, the MFA coverage correlator matches
Windows SFA logons to SurePassID MFA events. Configure via the
MfaCoveragesection.
Legacy Compatibility
The older single-source EventSource:Type configuration
is still supported:
{
"EventSource": {
"Type": "SurePassIdRestApi"
}
}When both EventSources and EventSource
sections are present, the multi-source EventSources section
takes priority and EventSource is ignored.
Migration: Replace EventSource:Type
with the corresponding entry in EventSources:
Legacy EventSource:Type |
New EventSources Key |
|---|---|
SurePassIdRestApi |
SurePassID: { Enabled: true } |
JsonFile |
JsonFile: { Enabled: true, DirectoryPath: "...", FilePattern: "..." } |
Syslog |
Syslog: { Enabled: true } |
WindowsEventLog |
WindowsEventLog: { Enabled: true } |
Environment Variable Overrides
export EventSources__SurePassID__Enabled="true"
export EventSources__WindowsEventLog__Enabled="true"
export EventSources__JsonFile__Enabled="false"Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| No events from one source | Source not enabled | Check EventSources:SourceName:Enabled is
true |
| Duplicate events | Same events in multiple sources | Use IgnoreSyncStatus: true only for compliance runs,
not continuous monitoring |
| Timeout on one source | Slow API or remote event log | Increase MaxEventsPerRequest or
MaxEventsPerQuery; check network connectivity |
| 0 events fetched in logs | Time range mismatch | Verify LookbackHours covers the period when events
occurred |
© 2024–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com