SurePassID SIEM Connector (formerely EventLogSYnc)
SIEM Connector
Version: 2026.1
Target Framework: .NET Framework 4.8
License: Proprietary - SurePassID Authentication,
Inc.
Overview
SIEM Connector is a Windows utility for synchronizing authentication event logs from SurePassID to various destinations including Windows Event Log, SIEM systems (via log4net), and file system exports.
Key Features
- REST API Integration - Sync events from SurePassID cloud or on-premise servers
- Multiple Output Targets - Windows Event Log, Log4Net (SIEM), File System
- Multiple Output Formats - JSON, Splunk JSON (NDJSON), Pipe-delimited Text
- Flexible Deployment - Run as console app, Windows Service, or scheduled task
- Date Range Filtering - Sync specific time periods
- Re-sync Capability - Ignore sync status to re-export historical data
What's New in 2026.1
- Modular Service Architecture - Pluggable data sources and output formatters
- REST API Format Selection - Choose JSON or piped format for data retrieval
- Date Range Filtering - Filter by
StartDateUtcandEndDateUtc - Ignore Sync Status - Re-sync previously exported events
- Batch Processing Fix - Consistent results regardless of batch size
Solution Structure
EventLogSync/
+-- Client/
| +-- EventLogSyncClientLib/ # Core library (.NET Framework 4.8)
| +-- EventLogSyncClientConsole/ # Console application
| \-- EventLogWriterClientConsole/ # Event writer utility
+-- EventLogSyncService/ # Windows Service
+-- EventLogSyncTests/ # Integration tests (MSTest)
+-- Submodules/
| +-- SurePassClientLibRest/ # REST API client (.NET Standard 2.0)
| \-- SurePassIdDotNetLibs/ # Shared libraries (.NET Standard 2.0)
\-- .github/copilot/copilot-instructions/copilot-external-md/
+-- EventLogSync-Administrator-Quick-Start-Guide.md
+-- EventLogSync-Configuration-Guide.md
+-- EventLogSync-Migration-Guide-2026.1.md
+-- EventLogSync-Release-Notes-2026.1.md
\-- EventLogSync-NET10-Migration-Plan.md
Quick Start
Prerequisites
- Windows Server 2016+ or Windows 10/11
- .NET Framework 4.8
- SurePassID API Key ID and API Key
Installation
- Install the msi from the download links.
- At a minimum, edit
appSettings.configwith your credentials:
<appSettings>
<add key="Server.ApiKeyId" value="YOUR_API_KEY_ID"/>
<add key="Server.ApiKey" value="YOUR_API_KEY"/>
<add key="Server.RESTEndPoint" value="https://your-server/api/mfa/v1"/>
<add key="Server.SyncTargetType" value="WindowsEventLog"/>
</appSettings>- Test the configuration:
.\EventLogSync.exe -maxsyncitems=10Running as a Windows Service
# Install the dedicated Windows Service
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe EventLogSyncService.exe
# Start the service
Start-Service -Name "SurePassID EventLogSync Service"See Administrator Quick Start Guide for detailed instructions.
Configuration
Key Parameters
| Parameter | Description | Default |
|---|---|---|
Server.ApiKeyId |
API Key ID | Required |
Server.ApiKey |
API Key Secret | Required |
Server.RESTEndPoint |
REST API URL | Required |
Server.SyncTargetType |
Output: WindowsEventLog, Log4Net, FileSystem | WindowsEventLog |
Server.RestApiFormat |
API format: json, piped | piped |
Server.RunOption |
Once or Continual | Once |
Output Formats
| Target | Format | Description |
|---|---|---|
| FileSystem | Json | Structured JSON with header |
| FileSystem | JsonSplunk | NDJSON (one event per line) |
| FileSystem | Text | Pipe-delimited text |
| WindowsEventLog | - | Windows Event Log entries |
| Log4Net | - | Configurable via log4net.config |
See Configuration Guide for complete reference.
Architecture
Service Architecture (2026.1)
+---------------------------------------------------------------------------+
| EventLogSyncService |
+---------------------------------------------------------------------------+
| |
| +-----------------------------+ +-----------------------------+ |
| | IEventLogDataSource | | IEventLogOutputFormatter | |
| +-----------------------------+ +-----------------------------+ |
| | RestApiDataSource | | JsonFileOutputFormatter | |
| | | | TextFileOutputFormatter | |
| | | | WindowsEventLogFormatter | |
| | | | Log4NetOutputFormatter | |
| +-----------------------------+ +-----------------------------+ |
| | | |
| +-------------------+-------------------+ |
| | |
| v |
| +---------------------------+ |
| | EventLogSyncService | |
| | (Orchestration) | |
| +---------------------------+ |
| |
+---------------------------------------------------------------------------+
Support
- Email: support@surepassid.com
- Portal: https://support.surepassid.com
- Documentation: https://docs.surepassid.com
License
This software is proprietary and confidential. Unauthorized copying, distribution, or use is strictly prohibited.
Version: 2026.1
Last Updated: March
2026
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com