SurePassID SIEM Connector (EventLogSync) Product Summary
SurePassID Authentication Server
SurePassID SIEM Connector (EventLogSync) — Product Summary
Tagline: Real-time MFA audit event synchronization for enterprise SIEM and compliance
What is SIEM Connector?
SIEM Connector (EventLogSync) is a lightweight Windows utility that continuously exports multi-factor authentication (MFA) audit events from the SurePassID MFA platform to your organization's Security Information and Event Management (SIEM) system or log store. It bridges the gap between your MFA infrastructure and your security operations center (SOC), enabling real-time visibility into authentication activity.
The Problem It Solves
Organizations deploying MFA need centralized visibility into authentication events for:
- Threat Detection — Identify brute-force attacks, credential stuffing, and account takeover attempts in real time
- Compliance — Meet audit trail requirements for SOC 2, HIPAA, PCI-DSS, NIST 800-53, and FedRAMP
- Incident Response — Correlate MFA events with other security telemetry during investigations
- Operational Monitoring — Track MFA adoption rates, failure patterns, and system health
Without EventLogSync, MFA events remain siloed in the SurePassID platform, invisible to your broader security monitoring ecosystem.
How It Works
- Connects to the SurePassID MFA REST API using secure API key authentication
- Fetches new audit events since the last synchronization checkpoint
- Transforms events into your preferred output format (JSON, Splunk, text, or native Windows events)
- Delivers formatted events to your chosen destination
- Repeats at a configurable interval (default: every 30 seconds)
Key Capabilities
Multi-Format Output
Export to JSON files, Splunk-compatible NDJSON, pipe-delimited text, Windows Event Log, or any Log4Net-supported target (including remote syslog).
Continuous or On-Demand
Run as a Windows Service for 24/7 synchronization, or execute on-demand for batch exports and testing.
Date Range Filtering
Re-export historical events by specifying start and end dates — ideal for compliance audits or backfilling a new SIEM deployment.
Configurable Sync Interval
Set the polling interval from seconds to minutes, balancing freshness against API load.
Secure by Design
- TLS 1.2/1.3 encrypted communications
- API key credentials isolated in a separate config file
- No passwords stored — uses revocable API keys generated in the SurePassID portal
Lightweight Footprint
Minimal resource consumption (~128 MB RAM, negligible CPU) — suitable for deployment on shared servers or domain controllers.
Deployment Options
| Mode | Best For |
|---|---|
| Windows Service | Production — automatic start, crash recovery, runs unattended |
| Console Application | Testing, debugging, one-time exports |
| Scheduled Task | Periodic batch exports without a persistent service |
SIEM Integrations
EventLogSync has been validated with:
| SIEM Platform | Integration Method |
|---|---|
| Splunk | File monitoring (NDJSON) or HEC via Log4Net |
| IBM QRadar | Syslog via Log4Net RemoteSyslogAppender |
| Microsoft Sentinel | Windows Event Log ? Azure Monitor Agent |
| Elastic/ELK | File monitoring (JSON) or Filebeat |
| Datadog | File tailing or Windows Event Log |
| Any syslog receiver | Log4Net RemoteSyslogAppender (RFC 5424) |
Rich Event Data
Every exported event includes:
- Who — Username, email, SSO identity
- What — Action performed, authentication method, result code
- When — UTC timestamp with millisecond precision
- Where — Client IPv4/IPv6 address
- How — Authentication method (OTP, Push, FIDO2, etc.)
- Context — Tenant name, API key name, token serial number
Version History Highlights
| Version | Key Feature |
|---|---|
| 2026.1 | Continuous sync wait interval fix, batch processing consistency |
| 25.4 | Modular service architecture, REST API format selection, date filtering |
| 25.3 | Modular config files, Log4Net integration |
| Pre-25.3 | Legacy monolithic configuration, WCF + Database modes |
Getting Started
# 1. Test connectivity (fetch 10 events, output to JSON file)
EventLogSync.exe -apikeyid=YOUR_KEY_ID -apikey=YOUR_SECRET ^
-restendpoint=https://your-server.surepassid.com/api/mfa/v1 ^
-syncapi=REST -targettype=f -maxsyncitems=10
# 2. Install as Windows Service for continuous operation
installutil EventLogSync.exe
net start EventLogSyncServiceRequirements
- Windows Server 2016+ or Windows 10+
- .NET Framework 4.8
- Network access (HTTPS) to your SurePassID MFA endpoint
- SurePassID API credentials (generated from the admin portal)
Licensing & Availability
EventLogSync is included at no additional cost with all SurePassID MFA platform subscriptions. It is distributed as a standalone Windows package — no agents, no cloud dependencies, no per-device fees.
Learn More
| Resource | Location |
|---|---|
| Configuration Guide | docs/ or
.github/copilot/copilot-instructions/copilot-external-md/ |
| Administrator Quick Start | Same directory |
| Migration Guide | Same directory |
| Release Notes | Same directory |
| Test Documentation | EventLogSyncTests/README.md |
Contact
SurePassID Corp.
Email: support@surepassid.com
Portal: https://support.surepassid.com
Website: https://www.surepassid.com
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com