SurePassID SIEM Connector Product Datasheet

SurePassID Authentication Server

SIEM Connector (EventLogSync) Product Datasheet

Version: 2026.1
Product: SIEM Connector
Vendor: SurePassID Corp.


Product Overview

SIEM Connector is an enterprise event log synchronization tool that exports multi-factor authentication (MFA) audit events from the SurePassID MFA platform to external Security Information and Event Management (SIEM) systems, file-based log stores, and Windows Event Log. It operates as a Windows Service or standalone console application, providing continuous or on-demand event synchronization.


Key Specifications

Attribute Value
Product Name SIEM Connector
Current Version 2026.1
Assembly Name EventLogSync.exe
Runtime .NET Framework 4.8
Platform Windows Server 2016 / 2019 / 2022, Windows 10/11
Deployment Mode Windows Service or Console Application
Data Source SurePassID MFA REST API
Authentication API Key ID + API Key (generated from SurePassID portal)
Protocol HTTPS (TLS 1.2 / TLS 1.3)

Architecture

+---------------------------------------------------------------------------+
|                               EventLogSync                                |
|                                                                           |
|  +-----------------------+     +---------------------------------------+  |
|  |     Data Sources      |     |           Output Formatters           |  |
|  |     ------------      |     |           -----------------           |  |
|  |                       |     |                                       |  |
|  |  - REST API           |---->|  - JSON File                          |  |
|  |    (json/piped)       |     |  - Splunk JSON (NDJSON)               |  |
|  +-----------------------+     |  - Text (pipe-delimited)              |  |
|                                |  - Windows Event Log                  |  |
|                                |  - Log4Net (Syslog, file, custom)     |  |
|                                +---------------------------------------+  |
|                                                                           |
+---------------------------------------------------------------------------+
               |                                     |
               v                                     v
   +-----------------------+     +---------------------------------------+
   |    SurePassID MFA     |     |         SIEM / Log Aggregator         |
   |       Platform        |     |        (Splunk, QRadar, etc.)         |
   +-----------------------+     +---------------------------------------+

Supported Output Targets

Target Format Use Case
JSON File Structured JSON with header and syncEvents array General SIEM ingestion, archival
Splunk JSON NDJSON (one JSON object per line) Splunk HTTP Event Collector (HEC)
Text File Pipe-delimited flat file Legacy systems, simple log parsing
Windows Event Log Windows Event entries (text or JSON body) Windows-native monitoring, SCOM
Log4Net Configurable via log4net appenders Syslog (RFC 5424), custom targets

Event Data Fields

Each synchronized event record contains:

Field Description Example
eventTime UTC timestamp 2026-03-15 14:22:01.123Z
tenant Account/tenant name Contoso
username User who triggered the event john.doe@contoso.com
action Event action type OTP Validation
severity Severity level SUCCESS, WARNING, SEVERE
eventResultCode Numeric result code 0 (success)
eventDescription Human-readable description OTP validated successfully
eventAuthenticationMethod Auth method used Otp, Push, Fido2
eventIpV4 Client IPv4 address 192.168.1.100
eventIpV6 Client IPv6 address ::1
eventSerialNumber Token serial number SN-12345678
eventApiKeyName API key name used Production-Key
ssoIdentity SSO provider identity azure-oid-abc123
userEmail User email address john.doe@contoso.com

Operating Modes

Mode Description Configuration
Continuous Runs indefinitely, syncing at a configurable interval Server.RunOption=c
Once Syncs available records and exits Server.RunOption=o
Windows Service Runs as a background service with auto-restart Install via installutil
Console Interactive execution for testing/debugging Run EventLogSync.exe directly

Configuration Parameters

Required

Parameter Description
Server.ApiKeyId API Key ID from SurePassID portal
Server.ApiKey API Key secret from SurePassID portal
Server.RESTEndPoint REST API endpoint URL
Server.SyncApi Must be REST

Sync Control

Parameter Default Description
Server.MaxSyncItems 0 (unlimited) Maximum records per sync cycle
Server.RunOption o (once) c = continuous, o = once
Server.ContinuousRunWaitTimeSeconds 30 Seconds between sync cycles
Server.RestApiFormat json json or piped
Server.IgnoreSyncStatus false Re-sync previously exported events
Server.StartDateUtc (none) Filter events after this UTC date
Server.EndDateUtc (none) Filter events before this UTC date

Output

Parameter Description
Server.SyncTargetType w = Windows Event Log, l = Log4Net, f = File System
Server.SyncTargetFileSystemFormat j = JSON, js = Splunk JSON, t = Text
Server.SystemName Tenant identifier in output

Security Features

  • TLS 1.2 and TLS 1.3 enforced for all API communications
  • API Key authentication (no user passwords stored)
  • Modular configuration files for credential isolation
  • Supports Windows file-system ACLs for config protection
  • No sensitive data written to export files beyond event content

System Requirements

Requirement Minimum
OS Windows Server 2016 or Windows 10
Runtime .NET Framework 4.8
Memory 128 MB available
Disk 50 MB + storage for export files
Network HTTPS outbound to SurePassID endpoint
Permissions Local admin (for Windows Event Log source creation and service install)

File Structure

C:\Program Files\SurePassID Corp\EventLogSync\
+-- EventLogSync.exe              # Main executable
+-- EventLogSync.exe.config       # .NET runtime config
+-- appSettings.config            # Application settings & credentials
+-- log4net.config                # Log4Net logging configuration
+-- Export\                       # Default export file directory
|   +-- SEIM_Export_*.json        # JSON export files
|   +-- SEIM_Export_*.txt         # Text export files
|   \-- log4net-output.txt        # Log4Net file output
\-- [supporting DLLs]

Integration Examples

Splunk (via file monitoring)

<add key="Server.SyncTargetType" value="f"/>
<add key="Server.SyncTargetFileSystemFormat" value="js"/>

Configure Splunk Universal Forwarder to monitor the Export\ directory.

Windows Event Log (for SCOM/Azure Monitor)

<add key="Server.SyncTargetType" value="w"/>

Events appear under the SurePassID event log with source SEIM_Export.

Syslog (via Log4Net RemoteSyslogAppender)

<add key="Server.SyncTargetType" value="l"/>

Configure log4net.config with RemoteSyslogAppender targeting your syslog server.


Licensing

EventLogSync is included with all SurePassID MFA platform subscriptions at no additional cost.


Support

Channel Contact
Email support@surepassid.com
Portal https://support.surepassid.com
Website https://www.surepassid.com

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com