SurePassID EventLogSync Microsoft Sentinel Ingestion Guide

SurePassID Authentication Server

SurePassID SIEM Connector (EventLogSync) – Microsoft Sentinel Ingestion Guide

This guide explains how to configure EventLogSync to export SurePassID authentication event logs and ingest them into Microsoft Sentinel (Azure Monitor / Log Analytics).

It covers the recommended output formats, the collection paths supported by Sentinel, the event schema produced by EventLogSync, and step-by-step configuration for the two most common approaches:

  1. Windows Event Log -> Azure Monitor Agent (AMA) (recommended for Windows hosts)
  2. JSON / NDJSON files -> Log Analytics ingestion (via AMA Custom Logs, Logstash, or the Logs Ingestion API)

1. Overview

EventLogSync pulls event log records from the SurePassId Authentication Server (via the REST API) and writes them to a configurable output target. For Sentinel ingestion, two of these targets are relevant:

Output Target (targettype) Description Sentinel Collection Method
e – Windows Event Log Writes records to the Windows Event Log (Text or JSON message body). Azure Monitor Agent (AMA) – Windows Event Logs DCR
f – File System (JSON/NDJSON) Writes records to timestamped .json files. AMA Custom Text Logs DCR, Logstash, or Logs Ingestion API

Recommendation: For Windows deployments, the Windows Event Log -> AMA path is the simplest and most reliable. Use the JSON/NDJSON file path when you need a raw structured feed or when routing through Logstash/the Logs Ingestion API to a custom table.


2. Event Schema

Each exported event contains the following fields (as emitted in JSON/NDJSON and in the JSON Windows Event Log message body):

Field Type Description
eventTime string Timestamp of the event (UTC).
tenant string SurePassId tenant (falls back to configured systemname).
username string Username associated with the event.
action string Action performed (e.g., authentication, provisioning).
severity string Event severity level.
eventResultCode int Numeric result/status code.
eventDescription string Human?readable event description.
eventIpV4 string Source IPv4 address.
eventIpV6 string Source IPv6 address.
eventApiKeyName string Name of the API key used.
eventSerialNumber string Token/device serial number.
eventAuthenticationMethod string Authentication method used.
ssoIdentity string External IdP identity (e.g., Azure AD ObjectId, SAML NameID).
userEmail string Email address of the user.

Structured JSON layout

When targetfilesystemformat = j (structured JSON), each file contains a header wrapper:

{
  "runDate": "2025-01-15 18:04:22.113Z",
  "eventCount": 2,
  "syncEvents": [
    {
      "eventTime": "2025-01-15T18:03:59Z",
      "tenant": "contoso",
      "username": "jdoe",
      "action": "UserAuthentication",
      "severity": "Information",
      "eventResultCode": 0,
      "eventDescription": "Authentication succeeded",
      "eventIpV4": "203.0.113.10",
      "eventIpV6": "",
      "eventApiKeyName": "EventLogSyncKey",
      "eventSerialNumber": "SP-000123",
      "eventAuthenticationMethod": "PushOTP",
      "ssoIdentity": "a1b2c3d4-...",
      "userEmail": "jdoe@contoso.com"
    }
  ]
}

NDJSON (Sentinel) layout

When targetfilesystemformat = s, each line is a single self-contained JSON object (no header wrapper). This is the recommended format for Sentinel file ingestion, because Sentinel’s custom log collectors process one record per line:

{"eventTime":"2025-01-15T18:03:59Z","tenant":"contoso","username":"jdoe","action":"UserAuthentication","severity":"Information","eventResultCode":0,"eventDescription":"Authentication succeeded","eventIpV4":"203.0.113.10","eventIpV6":"","eventApiKeyName":"EventLogSyncKey","eventSerialNumber":"SP-000123","eventAuthenticationMethod":"PushOTP","ssoIdentity":"a1b2c3d4-...","userEmail":"jdoe@contoso.com"}

3.1 Configure EventLogSync

Set the following in the application app.config (appSettings) or via command line:

<appSettings>
  <add key="Server.UseCommandLine" value="FALSE" />
  <add key="Server.ApiKeyId"   value="YOUR_API_KEY_ID" />
  <add key="Server.ApiKey"     value="YOUR_API_KEY" />
  <add key="Server.RESTEndPoint" value="https://your-server/api" />
  <add key="Server.SystemName" value="contoso" />

  <!-- Output to Windows Event Log -->
  <add key="Server.SyncTargetType" value="e" />
  <!-- Message body format: text (pipe-delimited) or json -->
  <add key="Server.SyncTargetFileSystemFormat" value="j" />
  <add key="Server.EventLogName" value="Application" />

  <!-- Continuous polling -->
  <add key="Server.RunOption" value="c" />
  <add key="Server.ContinuousRunWaitTimeSeconds" value="60" />
</appSettings>

Notes

  • Default event source name is SEIM_Export; default log name is Application.
  • Writing to a custom log (e.g., SurePass) requires administrator rights to create the event source the first time. Using Application avoids that requirement.
  • Choose a JSON message body (j) so the parser in Sentinel can extract fields cleanly.

3.2 Create a Data Collection Rule (DCR) in Azure

  1. In the Azure portal, open Monitor -> Data Collection Rules -> Create.
  2. Add the target Windows host(s) as Resources (requires the Azure Monitor Agent installed; Azure Arc for on-prem servers).
  3. Add a Windows Event Logs data source with an XPath query targeting the log/source used by EventLogSync, for example:
    Application!*[System[Provider[@Name='SEIM_Export']]]
  4. Set the destination to your Sentinel connected Log Analytics workspace.
  5. Save. Events flow into the Event table in Log Analytics.

3.3 Query in Sentinel

Event
| where Source == "SEIM_Export"
| extend Payload = parse_json(RenderedDescription)
| project TimeGenerated,
          EventTime      = tostring(Payload.eventTime),
          Tenant         = tostring(Payload.tenant),
          User           = tostring(Payload.username),
          Action         = tostring(Payload.action),
          Severity       = tostring(Payload.severity),
          ResultCode     = toint(Payload.eventResultCode),
          SourceIP       = tostring(Payload.eventIpV4),
          AuthMethod     = tostring(Payload.eventAuthenticationMethod),
          UserEmail      = tostring(Payload.userEmail)

If you configured a Text (pipe delimited) body instead of JSON, split RenderedDescription on the | character instead of using parse_json.


4. Approach B – JSON / NDJSON Files -> Log Analytics

Use this path when you prefer a file based feed or need a dedicated custom table.

4.1 Configure EventLogSync

<appSettings>
  <add key="Server.UseCommandLine" value="FALSE" />
  <add key="Server.ApiKeyId"   value="YOUR_API_KEY_ID" />
  <add key="Server.ApiKey"     value="YOUR_API_KEY" />
  <add key="Server.RESTEndPoint" value="https://your-server/api" />
  <add key="Server.SystemName" value="contoso" />

  <!-- Output to file system -->
  <add key="Server.SyncTargetType" value="f" />
  <!-- Use NDJSON (Splunk) so each line is one record -->
  <add key="Server.SyncTargetFileSystemFormat" value="s" />

  <add key="Server.RunOption" value="c" />
  <add key="Server.ContinuousRunWaitTimeSeconds" value="60" />
</appSettings>
  • Files are written to the Export folder next to the executable by default, named SEIM_Export_yyyyMMdd_HHmmss_fff.json.
  • Use NDJSON (s) for line based collectors. Structured JSON (j) wraps records in a syncEvents array with a header and is not line?delimited.

4.2 Choose a collection method

Option B1 – AMA Custom Text Logs (DCR based Custom Logs)

  1. Create a custom table (e.g., SurePassEventLog_CL) in your Log Analytics workspace.
  2. Create a Custom Text Logs DCR pointing at the export directory file pattern (e.g., C:\EventLogSync\Export\*.json).
  3. Use a KQL transform in the DCR to parse each NDJSON line into columns.
  4. Records land in SurePassEventLog_CL.

Option B2 – Logstash -> Log Analytics output plugin

  • Use a Logstash file input reading the export directory, a json filter, and the microsoft-sentinel-log-analytics-logstash-output-plugin to send to a custom table.

Option B3 – Logs Ingestion API (custom script)

  • A scheduled script reads each NDJSON file, batches the lines, and POSTs them to a Data Collection Endpoint (DCE) using the Logs Ingestion API against a custom DCR/table.

4.3 Query the custom table

SurePassEventLog_CL
| project TimeGenerated,
          EventTime  = eventTime_s,
          Tenant     = tenant_s,
          User       = username_s,
          Action     = action_s,
          Severity   = severity_s,
          ResultCode = eventResultCode_d,
          SourceIP   = eventIpV4_s,
          AuthMethod  = eventAuthenticationMethod_s,
          UserEmail  = userEmail_s

Column suffixes (_s, _d) are assigned by Log Analytics based on data type and depend on your DCR transform. Adjust names to match your table schema.


5. Operational Recommendations

  • Continuous mode: Run EventLogSync as a Windows Service (EventLogSyncService) with Server.RunOption = c and a sensible Server.ContinuousRunWaitTimeSeconds (e.g., 60) so events flow in near?real time without hammering the API.
  • Retention / cleanup (file path): When using file output, schedule cleanup of processed Export\*.json files, or configure your collector to delete/rotate after ingestion.
  • Time handling: eventTime is the source event time; Sentinel’s TimeGenerated reflects ingestion time. Use eventTime for accurate event chronology in analytics rules.
  • Field normalization (ASIM): Consider mapping to the Microsoft ASIM Authentication schema (e.g., EventType, TargetUsername, SrcIpAddr, EventResult) via a KQL function for cross?source correlation and out?of?the?box analytics.
  • Security: Protect the API key (Server.ApiKey) — store it securely and restrict access to the app.config. Restrict permissions on the Export directory.

6. Quick Reference

Setting Value for Sentinel (Event Log) Value for Sentinel (Files)
Server.SyncTargetType e f
Server.SyncTargetFileSystemFormat j (JSON message body) s (NDJSON)
Server.RunOption c c
Server.ContinuousRunWaitTimeSeconds 60 60
Sentinel collector Azure Monitor Agent (Windows Event Logs DCR) AMA Custom Text Logs / Logstash / Logs Ingestion API
Destination table Event Custom _CL table

For architecture details see EventLogSyncService-Architecture.md. For product overview see EventLogSync-Product-Datasheet.md and EventLogSync-Product-Summary.md.

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com