SurePassID SIEM Connector (formerely EventLogSYnc)

SIEM Connector

Version: 2026.1
Target Framework: .NET Framework 4.8
License: Proprietary - SurePassID Authentication, Inc.

Overview

SIEM Connector is a Windows utility for synchronizing authentication event logs from SurePassID to various destinations including Windows Event Log, SIEM systems (via log4net), and file system exports.

Key Features

  • REST API Integration - Sync events from SurePassID cloud or on-premise servers
  • Multiple Output Targets - Windows Event Log, Log4Net (SIEM), File System
  • Multiple Output Formats - JSON, Splunk JSON (NDJSON), Pipe-delimited Text
  • Flexible Deployment - Run as console app, Windows Service, or scheduled task
  • Date Range Filtering - Sync specific time periods
  • Re-sync Capability - Ignore sync status to re-export historical data

What's New in 2026.1

  • Modular Service Architecture - Pluggable data sources and output formatters
  • REST API Format Selection - Choose JSON or piped format for data retrieval
  • Date Range Filtering - Filter by StartDateUtc and EndDateUtc
  • Ignore Sync Status - Re-sync previously exported events
  • Batch Processing Fix - Consistent results regardless of batch size

Solution Structure

EventLogSync/
+-- Client/
|   +-- EventLogSyncClientLib/          # Core library (.NET Framework 4.8)
|   +-- EventLogSyncClientConsole/      # Console application
|   \-- EventLogWriterClientConsole/    # Event writer utility
+-- EventLogSyncService/                # Windows Service
+-- EventLogSyncTests/                  # Integration tests (MSTest)
+-- Submodules/
|   +-- SurePassClientLibRest/          # REST API client (.NET Standard 2.0)
|   \-- SurePassIdDotNetLibs/           # Shared libraries (.NET Standard 2.0)
\-- .github/copilot/copilot-instructions/copilot-external-md/
    +-- EventLogSync-Administrator-Quick-Start-Guide.md
    +-- EventLogSync-Configuration-Guide.md
    +-- EventLogSync-Migration-Guide-2026.1.md
    +-- EventLogSync-Release-Notes-2026.1.md
    \-- EventLogSync-NET10-Migration-Plan.md

Quick Start

Prerequisites

  • Windows Server 2016+ or Windows 10/11
  • .NET Framework 4.8
  • SurePassID API Key ID and API Key

Installation

  1. Install the msi from the download links.
  2. At a minimum, edit appSettings.config with your credentials:
<appSettings>
  <add key="Server.ApiKeyId" value="YOUR_API_KEY_ID"/>
  <add key="Server.ApiKey" value="YOUR_API_KEY"/>
  <add key="Server.RESTEndPoint" value="https://your-server/api/mfa/v1"/>
  <add key="Server.SyncTargetType" value="WindowsEventLog"/>
</appSettings>
  1. Test the configuration:
.\EventLogSync.exe -maxsyncitems=10

Running as a Windows Service

# Install the dedicated Windows Service
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe EventLogSyncService.exe

# Start the service
Start-Service -Name "SurePassID EventLogSync Service"

See Administrator Quick Start Guide for detailed instructions.

Configuration

Key Parameters

Parameter Description Default
Server.ApiKeyId API Key ID Required
Server.ApiKey API Key Secret Required
Server.RESTEndPoint REST API URL Required
Server.SyncTargetType Output: WindowsEventLog, Log4Net, FileSystem WindowsEventLog
Server.RestApiFormat API format: json, piped piped
Server.RunOption Once or Continual Once

Output Formats

Target Format Description
FileSystem Json Structured JSON with header
FileSystem JsonSplunk NDJSON (one event per line)
FileSystem Text Pipe-delimited text
WindowsEventLog - Windows Event Log entries
Log4Net - Configurable via log4net.config

See Configuration Guide for complete reference.

Architecture

Service Architecture (2026.1)

+---------------------------------------------------------------------------+
|                            EventLogSyncService                            |
+---------------------------------------------------------------------------+
|                                                                           |
| +-----------------------------+         +-----------------------------+   |
| |     IEventLogDataSource     |         |  IEventLogOutputFormatter   |   |
| +-----------------------------+         +-----------------------------+   |
| |   RestApiDataSource         |         |   JsonFileOutputFormatter   |   |
| |                             |         |   TextFileOutputFormatter   |   |
| |                             |         |   WindowsEventLogFormatter  |   |
| |                             |         |   Log4NetOutputFormatter    |   |
| +-----------------------------+         +-----------------------------+   |
|                |                                       |                  |
|                +-------------------+-------------------+                  |
|                                    |                                      |
|                                    v                                      |
|                      +---------------------------+                        |
|                      |    EventLogSyncService    |                        |
|                      |      (Orchestration)      |                        |
|                      +---------------------------+                        |
|                                                                           |
+---------------------------------------------------------------------------+

Support

License

This software is proprietary and confidential. Unauthorized copying, distribution, or use is strictly prohibited.


Version: 2026.1
Last Updated: March 2026

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com