SurePassID EventLogSync Splunk Ingestion Guide
SurePassID Authentication Server
SurePassID SEIM (EventLogSync) – Splunk Ingestion Guide
This guide explains how to configure EventLogSync to export SurePassId authentication event logs and ingest them into Splunk Enterprise or Splunk Cloud.
EventLogSync includes a purpose built NDJSON (Splunk) output format that produces one JSON event per line — the ideal shape for Splunk indexing. This guide covers that format, the recommended collection methods, the event schema, and step-by-step configuration.
1. Overview
EventLogSync pulls event log records from the SurePassID Authentication Server (via the REST API) and writes them to a configurable output target. For Splunk ingestion, two targets are relevant:
Output Target (targettype) |
Description | Splunk Collection Method |
|---|---|---|
f – File System (NDJSON) |
Writes one JSON event per line to timestamped .json
files. |
Universal/Heavy Forwarder monitor input, or
HTTP Event Collector via script |
e – Windows Event Log |
Writes records to the Windows Event Log (Text or JSON body). | Splunk Universal Forwarder with WinEventLog input |
Recommendation: Use the NDJSON (Splunk) file output (
targettype = f,targetfilesystemformat = s) with a Splunk Universal Forwarder monitoring the export directory. This is the simplest, most robust pipeline and matches Splunk’s line?oriented indexing model.
2. Event Schema
Each exported event contains the following fields:
| Field | Type | Description |
|---|---|---|
eventTime |
string | Timestamp of the event (UTC). |
tenant |
string | SurePassId tenant (falls back to configured
systemname). |
username |
string | Username associated with the event. |
action |
string | Action performed (e.g., authentication, provisioning). |
severity |
string | Event severity level. |
eventResultCode |
int | Numeric result/status code. |
eventDescription |
string | Human?readable event description. |
eventIpV4 |
string | Source IPv4 address. |
eventIpV6 |
string | Source IPv6 address. |
eventApiKeyName |
string | Name of the API key used. |
eventSerialNumber |
string | Token/device serial number. |
eventAuthenticationMethod |
string | Authentication method used. |
ssoIdentity |
string | External IdP identity (e.g., Azure AD ObjectId, SAML NameID). |
userEmail |
string | Email address of the user. |
NDJSON (Splunk) layout
When targetfilesystemformat = s, each line is a single
self?contained JSON object with no header wrapper —
perfect for Splunk’s INDEXED_EXTRACTIONS = json:
{"eventTime":"2025-01-15T18:03:59Z","tenant":"contoso","username":"jdoe","action":"UserAuthentication","severity":"Information","eventResultCode":0,"eventDescription":"Authentication succeeded","eventIpV4":"203.0.113.10","eventIpV6":"","eventApiKeyName":"EventLogSyncKey","eventSerialNumber":"SP-000123","eventAuthenticationMethod":"PushOTP","ssoIdentity":"a1b2c3d4-...","userEmail":"jdoe@contoso.com"}The alternative structured JSON format (
targetfilesystemformat = j) wraps events in arunDate/eventCount/syncEventsarray. Avoid it for Splunk — it is not line?delimited and requires custom line?breaking rules. Use NDJSON (s).
3. Configure EventLogSync for Splunk
Set the following in the application app.config
(appSettings) or via command line:
<appSettings>
<add key="Server.UseCommandLine" value="FALSE" />
<add key="Server.ApiKeyId" value="YOUR_API_KEY_ID" />
<add key="Server.ApiKey" value="YOUR_API_KEY" />
<add key="Server.RESTEndPoint" value="https://your-server/api" />
<add key="Server.SystemName" value="contoso" />
<!-- Output to file system as NDJSON (one JSON event per line) -->
<add key="Server.SyncTargetType" value="f" />
<add key="Server.SyncTargetFileSystemFormat" value="s" />
<!-- Continuous polling for near-real-time export -->
<add key="Server.RunOption" value="c" />
<add key="Server.ContinuousRunWaitTimeSeconds" value="60" />
</appSettings>- Files are written to the
Exportfolder next to the executable by default, namedSEIM_Export_yyyyMMdd_HHmmss_fff.json. - Run EventLogSync as the Windows Service
(
EventLogSyncService) in continuous mode for a steady feed.
4. Approach A – Universal Forwarder Monitor Input (Recommended)
4.1 Create an index (on the indexer / Splunk Cloud)
Create a dedicated index, e.g., surepass_events.
4.2 Configure
inputs.conf on the forwarder
On the host running EventLogSync, install the Splunk Universal Forwarder and add a monitor stanza pointing at the export directory:
# $SPLUNK_HOME/etc/system/local/inputs.conf
[monitor://C:\EventLogSync\Export\*.json]
disabled = false
sourcetype = surepass:eventlog
index = surepass_events
crcSalt = <SOURCE>4.3 Configure
props.conf for JSON extraction
On the indexer (or Heavy Forwarder), define the sourcetype so each line is parsed as JSON:
# $SPLUNK_HOME/etc/system/local/props.conf
[surepass:eventlog]
INDEXED_EXTRACTIONS = json
KV_MODE = none
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = "eventTime":"
TIME_FORMAT = %Y-%m-%dT%H:%M:%S%Z
MAX_TIMESTAMP_LOOKAHEAD = 40
TRUNCATE = 100000
TIME_PREFIX/TIME_FORMATset the event time from theeventTimefield instead of the file modification time. AdjustTIME_FORMATto match your actualeventTimestring.
4.4 Restart and verify
Restart the forwarder and indexer, then search:
index=surepass_events sourcetype="surepass:eventlog"
| table _time, tenant, username, action, severity, eventResultCode, eventIpV4, eventAuthenticationMethod, userEmail
5. Approach B – HTTP Event Collector (HEC)
Use HEC when you cannot install a forwarder on the EventLogSync host, or you want to push events directly.
5.1 Enable HEC and create a token
- In Splunk: Settings ? Data Inputs ? HTTP Event Collector ? New Token.
- Assign the
surepass_eventsindex and a sourcetype ofsurepass:eventlog. - Copy the generated token.
5.2 Forward NDJSON files to HEC
Because EventLogSync already writes one JSON object per line, a small
scheduled script can POST each line to the HEC
/services/collector/event (or /raw) endpoint.
Example (PowerShell):
$hec = "https://splunk.example.com:8088/services/collector/raw"
$token = "YOUR-HEC-TOKEN"
$dir = "C:\EventLogSync\Export"
Get-ChildItem "$dir\*.json" | ForEach-Object {
$body = Get-Content $_.FullName -Raw
Invoke-RestMethod -Uri $hec -Method Post `
-Headers @{ Authorization = "Splunk $token" } `
-Body $body -ContentType "application/json"
Remove-Item $_.FullName # remove after successful ingest
}Using the
/rawendpoint with an NDJSON body lets Splunk apply the sourcetype’sINDEXED_EXTRACTIONS = jsonconfiguration to each line.
6. Approach C – Windows Event Log (Universal Forwarder)
If you prefer to route through the Windows Event Log:
- Configure EventLogSync with
Server.SyncTargetType = eandServer.SyncTargetFileSystemFormat = j(JSON message body). Default source name isSEIM_Export, default log isApplication. - Configure the Universal Forwarder
inputs.conf:[WinEventLog://Application] disabled = false index = surepass_events sourcetype = surepass:winevent renderXml = false - Filter/extract on the
SEIM_Exportsource and parse the JSON message body withspath:index=surepass_events sourcetype="surepass:winevent" SourceName="SEIM_Export" | spath input=Message | table _time, tenant, username, action, severity, eventResultCode
7. Operational Recommendations
- Continuous mode: Run the
EventLogSyncServiceWindows Service withServer.RunOption = cand a sensibleServer.ContinuousRunWaitTimeSeconds(e.g., 60) for near?real?time ingestion. - File cleanup: When forwarding files, delete or
rotate processed
Export\*.jsonfiles after ingestion (the HEC script above removes them on success).crcSalt = <SOURCE>prevents the forwarder from re?reading rotated files with identical headers. - Event time: Configure
TIME_PREFIX/TIME_FORMATso Splunk useseventTimerather than file time for accurate event chronology. - Field naming: With
INDEXED_EXTRACTIONS = json, fields are auto?extracted using the JSON key names (tenant,username,action, …) — no manual field extraction required. - Security: Protect the API key
(
Server.ApiKey) and restrict permissions on theExportdirectory and any HEC tokens. - CIM mapping: Consider mapping fields to the Splunk
Common Information Model Authentication data model
(
user,src,action,app) via field aliases/calculated fields for use with prebuilt security content.
8. Quick Reference
| Setting | Recommended value for Splunk |
|---|---|
Server.SyncTargetType |
f (file system) |
Server.SyncTargetFileSystemFormat |
s (NDJSON / Splunk) |
Server.RunOption |
c (continuous) |
Server.ContinuousRunWaitTimeSeconds |
60 |
| Splunk sourcetype | surepass:eventlog |
| Splunk index | surepass_events |
| Collection method | Universal Forwarder monitor input (recommended), HEC, or WinEventLog |
For architecture details see
EventLogSyncService-Architecture.md. For the Sentinel
equivalent see EventLogSync-Sentinel-Ingestion-Guide.md.
For product overview see EventLogSync-Product-Datasheet.md
and
EventLogSync-Product-Summary.md.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com