SurePassID SIEM Connector Product Datasheet
SurePassID Authentication Server
SIEM Connector (EventLogSync) Product Datasheet
Version: 2026.1
Product: SIEM Connector
Vendor: SurePassID Corp.
Product Overview
SIEM Connector is an enterprise event log synchronization tool that exports multi-factor authentication (MFA) audit events from the SurePassID MFA platform to external Security Information and Event Management (SIEM) systems, file-based log stores, and Windows Event Log. It operates as a Windows Service or standalone console application, providing continuous or on-demand event synchronization.
Key Specifications
| Attribute | Value |
|---|---|
| Product Name | SIEM Connector |
| Current Version | 2026.1 |
| Assembly Name | EventLogSync.exe |
| Runtime | .NET Framework 4.8 |
| Platform | Windows Server 2016 / 2019 / 2022, Windows 10/11 |
| Deployment Mode | Windows Service or Console Application |
| Data Source | SurePassID MFA REST API |
| Authentication | API Key ID + API Key (generated from SurePassID portal) |
| Protocol | HTTPS (TLS 1.2 / TLS 1.3) |
Architecture
+---------------------------------------------------------------------------+
| EventLogSync |
| |
| +-----------------------+ +---------------------------------------+ |
| | Data Sources | | Output Formatters | |
| | ------------ | | ----------------- | |
| | | | | |
| | - REST API |---->| - JSON File | |
| | (json/piped) | | - Splunk JSON (NDJSON) | |
| +-----------------------+ | - Text (pipe-delimited) | |
| | - Windows Event Log | |
| | - Log4Net (Syslog, file, custom) | |
| +---------------------------------------+ |
| |
+---------------------------------------------------------------------------+
| |
v v
+-----------------------+ +---------------------------------------+
| SurePassID MFA | | SIEM / Log Aggregator |
| Platform | | (Splunk, QRadar, etc.) |
+-----------------------+ +---------------------------------------+
Supported Output Targets
| Target | Format | Use Case |
|---|---|---|
| JSON File | Structured JSON with header and syncEvents array |
General SIEM ingestion, archival |
| Splunk JSON | NDJSON (one JSON object per line) | Splunk HTTP Event Collector (HEC) |
| Text File | Pipe-delimited flat file | Legacy systems, simple log parsing |
| Windows Event Log | Windows Event entries (text or JSON body) | Windows-native monitoring, SCOM |
| Log4Net | Configurable via log4net appenders | Syslog (RFC 5424), custom targets |
Event Data Fields
Each synchronized event record contains:
| Field | Description | Example |
|---|---|---|
eventTime |
UTC timestamp | 2026-03-15 14:22:01.123Z |
tenant |
Account/tenant name | Contoso |
username |
User who triggered the event | john.doe@contoso.com |
action |
Event action type | OTP Validation |
severity |
Severity level | SUCCESS, WARNING, SEVERE |
eventResultCode |
Numeric result code | 0 (success) |
eventDescription |
Human-readable description | OTP validated successfully |
eventAuthenticationMethod |
Auth method used | Otp, Push, Fido2 |
eventIpV4 |
Client IPv4 address | 192.168.1.100 |
eventIpV6 |
Client IPv6 address | ::1 |
eventSerialNumber |
Token serial number | SN-12345678 |
eventApiKeyName |
API key name used | Production-Key |
ssoIdentity |
SSO provider identity | azure-oid-abc123 |
userEmail |
User email address | john.doe@contoso.com |
Operating Modes
| Mode | Description | Configuration |
|---|---|---|
| Continuous | Runs indefinitely, syncing at a configurable interval | Server.RunOption=c |
| Once | Syncs available records and exits | Server.RunOption=o |
| Windows Service | Runs as a background service with auto-restart | Install via installutil |
| Console | Interactive execution for testing/debugging | Run EventLogSync.exe directly |
Configuration Parameters
Required
| Parameter | Description |
|---|---|
Server.ApiKeyId |
API Key ID from SurePassID portal |
Server.ApiKey |
API Key secret from SurePassID portal |
Server.RESTEndPoint |
REST API endpoint URL |
Server.SyncApi |
Must be REST |
Sync Control
| Parameter | Default | Description |
|---|---|---|
Server.MaxSyncItems |
0 (unlimited) |
Maximum records per sync cycle |
Server.RunOption |
o (once) |
c = continuous, o = once |
Server.ContinuousRunWaitTimeSeconds |
30 |
Seconds between sync cycles |
Server.RestApiFormat |
json |
json or piped |
Server.IgnoreSyncStatus |
false |
Re-sync previously exported events |
Server.StartDateUtc |
(none) | Filter events after this UTC date |
Server.EndDateUtc |
(none) | Filter events before this UTC date |
Output
| Parameter | Description |
|---|---|
Server.SyncTargetType |
w = Windows Event Log, l = Log4Net,
f = File System |
Server.SyncTargetFileSystemFormat |
j = JSON, js = Splunk JSON, t
= Text |
Server.SystemName |
Tenant identifier in output |
Security Features
- TLS 1.2 and TLS 1.3 enforced for all API communications
- API Key authentication (no user passwords stored)
- Modular configuration files for credential isolation
- Supports Windows file-system ACLs for config protection
- No sensitive data written to export files beyond event content
System Requirements
| Requirement | Minimum |
|---|---|
| OS | Windows Server 2016 or Windows 10 |
| Runtime | .NET Framework 4.8 |
| Memory | 128 MB available |
| Disk | 50 MB + storage for export files |
| Network | HTTPS outbound to SurePassID endpoint |
| Permissions | Local admin (for Windows Event Log source creation and service install) |
File Structure
C:\Program Files\SurePassID Corp\EventLogSync\
+-- EventLogSync.exe # Main executable
+-- EventLogSync.exe.config # .NET runtime config
+-- appSettings.config # Application settings & credentials
+-- log4net.config # Log4Net logging configuration
+-- Export\ # Default export file directory
| +-- SEIM_Export_*.json # JSON export files
| +-- SEIM_Export_*.txt # Text export files
| \-- log4net-output.txt # Log4Net file output
\-- [supporting DLLs]
Integration Examples
Splunk (via file monitoring)
<add key="Server.SyncTargetType" value="f"/>
<add key="Server.SyncTargetFileSystemFormat" value="js"/>Configure Splunk Universal Forwarder to monitor the
Export\ directory.
Windows Event Log (for SCOM/Azure Monitor)
<add key="Server.SyncTargetType" value="w"/>Events appear under the SurePassID event log with source
SEIM_Export.
Syslog (via Log4Net RemoteSyslogAppender)
<add key="Server.SyncTargetType" value="l"/>Configure log4net.config with
RemoteSyslogAppender targeting your syslog server.
Licensing
EventLogSync is included with all SurePassID MFA platform subscriptions at no additional cost.
Support
| Channel | Contact |
|---|---|
| support@surepassid.com | |
| Portal | https://support.surepassid.com |
| Website | https://www.surepassid.com |
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com