SurePassID Compliance Manager Datasheet: HIPAA and CMMC 2.0

SurePassID Authentication Server

Multiple Event Sources

Last Updated: July 2025

The compliance system supports ingesting authentication events from multiple sources simultaneously. When multiple sources are enabled, events are fetched in parallel and merged chronologically using AggregateEventSource.


Configuration

Enable multiple sources in the EventSources section of appsettings.json:

{
  "EventSources": {
    "SurePassID": { "Enabled": true },
    "WindowsEventLog": { "Enabled": true },
    "JsonFile": {
      "Enabled": false,
      "DirectoryPath": "./Events",
      "FilePattern": "*.json"
    },
    "Syslog": { "Enabled": false }
  }
}

Each source has its own top-level configuration section for detailed settings.


Available Sources

Source Config Key Top-Level Section Description
SurePassID REST API EventSources:SurePassID SurePassID Real-time MFA events from SurePassID server
Windows Event Log EventSources:WindowsEventLog WindowsEventLog AD login events (Security log 4624, 4625, etc.)
JSON Files EventSources:JsonFile (inline) SIEM exports (Splunk, Sentinel)
Syslog EventSources:Syslog (inline) RFC 5424/3164/CEF log files
Entra ID EventSources:EntraIdJson / EntraIdGraph EntraId Azure AD sign-in logs

Common Multi-Source Combinations

Correlates MFA events from SurePassID with AD logon events from the Security log:

{
  "EventSources": {
    "SurePassID": { "Enabled": true },
    "WindowsEventLog": { "Enabled": true }
  },
  "SurePassID": {
    "Endpoint": "https://mfa.company.com/api/mfa/v1",
    "ApiKeyId": "compliance-api",
    "ApiKey": "your-api-key",
    "IgnoreSyncStatus": true,
    "PreferJsonBulkFormat": true
  },
  "WindowsEventLog": {
    "LogName": "Security",
    "ComputerNames": ["dc01.company.com"],
    "IncludeSuccessfulLogons": true,
    "IncludeFailedLogons": true,
    "ExcludeMachineAccounts": true,
    "ExcludeSystemAccounts": true,
    "MaxEventsPerQuery": 10000
  },
  "ActiveDirectory": {
    "Server": "dc01.company.com",
    "BaseDn": "DC=company,DC=com",
    "UseIntegratedAuth": true
  }
}

SurePassID + JSON File Import

Supplement real-time MFA data with historical SIEM exports:

{
  "EventSources": {
    "SurePassID": { "Enabled": true },
    "JsonFile": {
      "Enabled": true,
      "DirectoryPath": "C:\\Logs\\SiemExports",
      "FilePattern": "*.json"
    }
  }
}

How It Works

  1. Registration: At startup, the CLI, service, or MCP server registers an IAuthEventSource for each enabled source.
  2. Aggregation: When more than one source is registered, an AggregateEventSource wraps them.
  3. Parallel Fetch: AggregateEventSource.FetchAsync() calls each source concurrently.
  4. Merge: Results are combined into a single list sorted by event timestamp (UTC-normalized).
  5. Fault Tolerance: If one source fails, the others still return their events. Failures are logged as warnings.
  6. MFA Coverage: When both Windows Event Log and SurePassID sources are active, the MFA coverage correlator matches Windows SFA logons to SurePassID MFA events. Configure via the MfaCoverage section.

Legacy Compatibility

The older single-source EventSource:Type configuration is still supported:

{
  "EventSource": {
    "Type": "SurePassIdRestApi"
  }
}

When both EventSources and EventSource sections are present, the multi-source EventSources section takes priority and EventSource is ignored.

Migration: Replace EventSource:Type with the corresponding entry in EventSources:

Legacy EventSource:Type New EventSources Key
SurePassIdRestApi SurePassID: { Enabled: true }
JsonFile JsonFile: { Enabled: true, DirectoryPath: "...", FilePattern: "..." }
Syslog Syslog: { Enabled: true }
WindowsEventLog WindowsEventLog: { Enabled: true }

Environment Variable Overrides

export EventSources__SurePassID__Enabled="true"
export EventSources__WindowsEventLog__Enabled="true"
export EventSources__JsonFile__Enabled="false"

Troubleshooting

Symptom Cause Fix
No events from one source Source not enabled Check EventSources:SourceName:Enabled is true
Duplicate events Same events in multiple sources Use IgnoreSyncStatus: true only for compliance runs, not continuous monitoring
Timeout on one source Slow API or remote event log Increase MaxEventsPerRequest or MaxEventsPerQuery; check network connectivity
0 events fetched in logs Time range mismatch Verify LookbackHours covers the period when events occurred
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com