SurePassID EventLogSync Microsoft Sentinel Ingestion Guide
SurePassID Authentication Server
SurePassID SIEM Connector (EventLogSync) – Microsoft Sentinel Ingestion Guide
This guide explains how to configure EventLogSync to export SurePassID authentication event logs and ingest them into Microsoft Sentinel (Azure Monitor / Log Analytics).
It covers the recommended output formats, the collection paths supported by Sentinel, the event schema produced by EventLogSync, and step-by-step configuration for the two most common approaches:
- Windows Event Log -> Azure Monitor Agent (AMA) (recommended for Windows hosts)
- JSON / NDJSON files -> Log Analytics ingestion (via AMA Custom Logs, Logstash, or the Logs Ingestion API)
1. Overview
EventLogSync pulls event log records from the SurePassId Authentication Server (via the REST API) and writes them to a configurable output target. For Sentinel ingestion, two of these targets are relevant:
Output Target (targettype) |
Description | Sentinel Collection Method |
|---|---|---|
e – Windows Event Log |
Writes records to the Windows Event Log (Text or JSON message body). | Azure Monitor Agent (AMA) – Windows Event Logs DCR |
f – File System (JSON/NDJSON) |
Writes records to timestamped .json files. |
AMA Custom Text Logs DCR, Logstash, or Logs Ingestion API |
Recommendation: For Windows deployments, the Windows Event Log -> AMA path is the simplest and most reliable. Use the JSON/NDJSON file path when you need a raw structured feed or when routing through Logstash/the Logs Ingestion API to a custom table.
2. Event Schema
Each exported event contains the following fields (as emitted in JSON/NDJSON and in the JSON Windows Event Log message body):
| Field | Type | Description |
|---|---|---|
eventTime |
string | Timestamp of the event (UTC). |
tenant |
string | SurePassId tenant (falls back to configured
systemname). |
username |
string | Username associated with the event. |
action |
string | Action performed (e.g., authentication, provisioning). |
severity |
string | Event severity level. |
eventResultCode |
int | Numeric result/status code. |
eventDescription |
string | Human?readable event description. |
eventIpV4 |
string | Source IPv4 address. |
eventIpV6 |
string | Source IPv6 address. |
eventApiKeyName |
string | Name of the API key used. |
eventSerialNumber |
string | Token/device serial number. |
eventAuthenticationMethod |
string | Authentication method used. |
ssoIdentity |
string | External IdP identity (e.g., Azure AD ObjectId, SAML NameID). |
userEmail |
string | Email address of the user. |
Structured JSON layout
When targetfilesystemformat = j (structured JSON), each
file contains a header wrapper:
{
"runDate": "2025-01-15 18:04:22.113Z",
"eventCount": 2,
"syncEvents": [
{
"eventTime": "2025-01-15T18:03:59Z",
"tenant": "contoso",
"username": "jdoe",
"action": "UserAuthentication",
"severity": "Information",
"eventResultCode": 0,
"eventDescription": "Authentication succeeded",
"eventIpV4": "203.0.113.10",
"eventIpV6": "",
"eventApiKeyName": "EventLogSyncKey",
"eventSerialNumber": "SP-000123",
"eventAuthenticationMethod": "PushOTP",
"ssoIdentity": "a1b2c3d4-...",
"userEmail": "jdoe@contoso.com"
}
]
}NDJSON (Sentinel) layout
When targetfilesystemformat = s, each line is a single
self-contained JSON object (no header wrapper). This is the
recommended format for Sentinel file ingestion, because
Sentinel’s custom log collectors process one record per line:
{"eventTime":"2025-01-15T18:03:59Z","tenant":"contoso","username":"jdoe","action":"UserAuthentication","severity":"Information","eventResultCode":0,"eventDescription":"Authentication succeeded","eventIpV4":"203.0.113.10","eventIpV6":"","eventApiKeyName":"EventLogSyncKey","eventSerialNumber":"SP-000123","eventAuthenticationMethod":"PushOTP","ssoIdentity":"a1b2c3d4-...","userEmail":"jdoe@contoso.com"}3. Approach A – Windows Event Log -> Azure Monitor Agent (Recommended)
3.1 Configure EventLogSync
Set the following in the application app.config
(appSettings) or via command line:
<appSettings>
<add key="Server.UseCommandLine" value="FALSE" />
<add key="Server.ApiKeyId" value="YOUR_API_KEY_ID" />
<add key="Server.ApiKey" value="YOUR_API_KEY" />
<add key="Server.RESTEndPoint" value="https://your-server/api" />
<add key="Server.SystemName" value="contoso" />
<!-- Output to Windows Event Log -->
<add key="Server.SyncTargetType" value="e" />
<!-- Message body format: text (pipe-delimited) or json -->
<add key="Server.SyncTargetFileSystemFormat" value="j" />
<add key="Server.EventLogName" value="Application" />
<!-- Continuous polling -->
<add key="Server.RunOption" value="c" />
<add key="Server.ContinuousRunWaitTimeSeconds" value="60" />
</appSettings>Notes
- Default event source name is
SEIM_Export; default log name isApplication. - Writing to a custom log (e.g.,
SurePass) requires administrator rights to create the event source the first time. UsingApplicationavoids that requirement. - Choose a JSON message body (
j) so the parser in Sentinel can extract fields cleanly.
3.2 Create a Data Collection Rule (DCR) in Azure
- In the Azure portal, open Monitor -> Data Collection Rules -> Create.
- Add the target Windows host(s) as Resources (requires the Azure Monitor Agent installed; Azure Arc for on-prem servers).
- Add a Windows Event Logs data source with an XPath
query targeting the log/source used by EventLogSync, for example:
Application!*[System[Provider[@Name='SEIM_Export']]] - Set the destination to your Sentinel connected Log Analytics workspace.
- Save. Events flow into the
Eventtable in Log Analytics.
3.3 Query in Sentinel
Event
| where Source == "SEIM_Export"
| extend Payload = parse_json(RenderedDescription)
| project TimeGenerated,
EventTime = tostring(Payload.eventTime),
Tenant = tostring(Payload.tenant),
User = tostring(Payload.username),
Action = tostring(Payload.action),
Severity = tostring(Payload.severity),
ResultCode = toint(Payload.eventResultCode),
SourceIP = tostring(Payload.eventIpV4),
AuthMethod = tostring(Payload.eventAuthenticationMethod),
UserEmail = tostring(Payload.userEmail)
If you configured a Text (pipe delimited) body instead of JSON, split
RenderedDescriptionon the|character instead of usingparse_json.
4. Approach B – JSON / NDJSON Files -> Log Analytics
Use this path when you prefer a file based feed or need a dedicated custom table.
4.1 Configure EventLogSync
<appSettings>
<add key="Server.UseCommandLine" value="FALSE" />
<add key="Server.ApiKeyId" value="YOUR_API_KEY_ID" />
<add key="Server.ApiKey" value="YOUR_API_KEY" />
<add key="Server.RESTEndPoint" value="https://your-server/api" />
<add key="Server.SystemName" value="contoso" />
<!-- Output to file system -->
<add key="Server.SyncTargetType" value="f" />
<!-- Use NDJSON (Splunk) so each line is one record -->
<add key="Server.SyncTargetFileSystemFormat" value="s" />
<add key="Server.RunOption" value="c" />
<add key="Server.ContinuousRunWaitTimeSeconds" value="60" />
</appSettings>- Files are written to the
Exportfolder next to the executable by default, namedSEIM_Export_yyyyMMdd_HHmmss_fff.json. - Use NDJSON (
s) for line based collectors. Structured JSON (j) wraps records in asyncEventsarray with a header and is not line?delimited.
4.2 Choose a collection method
Option B1 – AMA Custom Text Logs (DCR based Custom Logs)
- Create a custom table (e.g.,
SurePassEventLog_CL) in your Log Analytics workspace. - Create a Custom Text Logs DCR pointing at the
export directory file pattern (e.g.,
C:\EventLogSync\Export\*.json). - Use a KQL transform in the DCR to parse each NDJSON line into columns.
- Records land in
SurePassEventLog_CL.
Option B2 – Logstash -> Log Analytics output plugin
- Use a Logstash
fileinput reading the export directory, ajsonfilter, and themicrosoft-sentinel-log-analytics-logstash-output-pluginto send to a custom table.
Option B3 – Logs Ingestion API (custom script)
- A scheduled script reads each NDJSON file, batches the lines, and POSTs them to a Data Collection Endpoint (DCE) using the Logs Ingestion API against a custom DCR/table.
4.3 Query the custom table
SurePassEventLog_CL
| project TimeGenerated,
EventTime = eventTime_s,
Tenant = tenant_s,
User = username_s,
Action = action_s,
Severity = severity_s,
ResultCode = eventResultCode_d,
SourceIP = eventIpV4_s,
AuthMethod = eventAuthenticationMethod_s,
UserEmail = userEmail_s
Column suffixes (
_s,_d) are assigned by Log Analytics based on data type and depend on your DCR transform. Adjust names to match your table schema.
5. Operational Recommendations
- Continuous mode: Run EventLogSync as a Windows
Service (
EventLogSyncService) withServer.RunOption = cand a sensibleServer.ContinuousRunWaitTimeSeconds(e.g., 60) so events flow in near?real time without hammering the API. - Retention / cleanup (file path): When using file
output, schedule cleanup of processed
Export\*.jsonfiles, or configure your collector to delete/rotate after ingestion. - Time handling:
eventTimeis the source event time; Sentinel’sTimeGeneratedreflects ingestion time. UseeventTimefor accurate event chronology in analytics rules. - Field normalization (ASIM): Consider mapping to the
Microsoft ASIM Authentication schema (e.g.,
EventType,TargetUsername,SrcIpAddr,EventResult) via a KQL function for cross?source correlation and out?of?the?box analytics. - Security: Protect the API key
(
Server.ApiKey) — store it securely and restrict access to theapp.config. Restrict permissions on theExportdirectory.
6. Quick Reference
| Setting | Value for Sentinel (Event Log) | Value for Sentinel (Files) |
|---|---|---|
Server.SyncTargetType |
e |
f |
Server.SyncTargetFileSystemFormat |
j (JSON message body) |
s (NDJSON) |
Server.RunOption |
c |
c |
Server.ContinuousRunWaitTimeSeconds |
60 |
60 |
| Sentinel collector | Azure Monitor Agent (Windows Event Logs DCR) | AMA Custom Text Logs / Logstash / Logs Ingestion API |
| Destination table | Event |
Custom _CL table |
For architecture details see
EventLogSyncService-Architecture.md. For product overview
see EventLogSync-Product-Datasheet.md and
EventLogSync-Product-Summary.md.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com