SurePassID SIEM Connector (EventLogSync) Product Summary

SurePassID Authentication Server

SurePassID SIEM Connector (EventLogSync) — Product Summary

Tagline: Real-time MFA audit event synchronization for enterprise SIEM and compliance


What is SIEM Connector?

SIEM Connector (EventLogSync) is a lightweight Windows utility that continuously exports multi-factor authentication (MFA) audit events from the SurePassID MFA platform to your organization's Security Information and Event Management (SIEM) system or log store. It bridges the gap between your MFA infrastructure and your security operations center (SOC), enabling real-time visibility into authentication activity.


The Problem It Solves

Organizations deploying MFA need centralized visibility into authentication events for:

  • Threat Detection — Identify brute-force attacks, credential stuffing, and account takeover attempts in real time
  • Compliance — Meet audit trail requirements for SOC 2, HIPAA, PCI-DSS, NIST 800-53, and FedRAMP
  • Incident Response — Correlate MFA events with other security telemetry during investigations
  • Operational Monitoring — Track MFA adoption rates, failure patterns, and system health

Without EventLogSync, MFA events remain siloed in the SurePassID platform, invisible to your broader security monitoring ecosystem.


How It Works

  1. Connects to the SurePassID MFA REST API using secure API key authentication
  2. Fetches new audit events since the last synchronization checkpoint
  3. Transforms events into your preferred output format (JSON, Splunk, text, or native Windows events)
  4. Delivers formatted events to your chosen destination
  5. Repeats at a configurable interval (default: every 30 seconds)

Key Capabilities

Multi-Format Output

Export to JSON files, Splunk-compatible NDJSON, pipe-delimited text, Windows Event Log, or any Log4Net-supported target (including remote syslog).

Continuous or On-Demand

Run as a Windows Service for 24/7 synchronization, or execute on-demand for batch exports and testing.

Date Range Filtering

Re-export historical events by specifying start and end dates — ideal for compliance audits or backfilling a new SIEM deployment.

Configurable Sync Interval

Set the polling interval from seconds to minutes, balancing freshness against API load.

Secure by Design

  • TLS 1.2/1.3 encrypted communications
  • API key credentials isolated in a separate config file
  • No passwords stored — uses revocable API keys generated in the SurePassID portal

Lightweight Footprint

Minimal resource consumption (~128 MB RAM, negligible CPU) — suitable for deployment on shared servers or domain controllers.


Deployment Options

Mode Best For
Windows Service Production — automatic start, crash recovery, runs unattended
Console Application Testing, debugging, one-time exports
Scheduled Task Periodic batch exports without a persistent service

SIEM Integrations

EventLogSync has been validated with:

SIEM Platform Integration Method
Splunk File monitoring (NDJSON) or HEC via Log4Net
IBM QRadar Syslog via Log4Net RemoteSyslogAppender
Microsoft Sentinel Windows Event Log ? Azure Monitor Agent
Elastic/ELK File monitoring (JSON) or Filebeat
Datadog File tailing or Windows Event Log
Any syslog receiver Log4Net RemoteSyslogAppender (RFC 5424)

Rich Event Data

Every exported event includes:

  • Who — Username, email, SSO identity
  • What — Action performed, authentication method, result code
  • When — UTC timestamp with millisecond precision
  • Where — Client IPv4/IPv6 address
  • How — Authentication method (OTP, Push, FIDO2, etc.)
  • Context — Tenant name, API key name, token serial number

Version History Highlights

Version Key Feature
2026.1 Continuous sync wait interval fix, batch processing consistency
25.4 Modular service architecture, REST API format selection, date filtering
25.3 Modular config files, Log4Net integration
Pre-25.3 Legacy monolithic configuration, WCF + Database modes

Getting Started

# 1. Test connectivity (fetch 10 events, output to JSON file)
EventLogSync.exe -apikeyid=YOUR_KEY_ID -apikey=YOUR_SECRET ^
  -restendpoint=https://your-server.surepassid.com/api/mfa/v1 ^
  -syncapi=REST -targettype=f -maxsyncitems=10

# 2. Install as Windows Service for continuous operation
installutil EventLogSync.exe
net start EventLogSyncService

Requirements

  • Windows Server 2016+ or Windows 10+
  • .NET Framework 4.8
  • Network access (HTTPS) to your SurePassID MFA endpoint
  • SurePassID API credentials (generated from the admin portal)

Licensing & Availability

EventLogSync is included at no additional cost with all SurePassID MFA platform subscriptions. It is distributed as a standalone Windows package — no agents, no cloud dependencies, no per-device fees.


Learn More

Resource Location
Configuration Guide docs/ or .github/copilot/copilot-instructions/copilot-external-md/
Administrator Quick Start Same directory
Migration Guide Same directory
Release Notes Same directory
Test Documentation EventLogSyncTests/README.md

Contact

SurePassID Corp.
Email: support@surepassid.com
Portal: https://support.surepassid.com
Website: https://www.surepassid.com


SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com