SurePassID EventLogSync Splunk Ingestion Guide

SurePassID Authentication Server

SurePassID SEIM (EventLogSync) – Splunk Ingestion Guide

This guide explains how to configure EventLogSync to export SurePassId authentication event logs and ingest them into Splunk Enterprise or Splunk Cloud.

EventLogSync includes a purpose built NDJSON (Splunk) output format that produces one JSON event per line — the ideal shape for Splunk indexing. This guide covers that format, the recommended collection methods, the event schema, and step-by-step configuration.


1. Overview

EventLogSync pulls event log records from the SurePassID Authentication Server (via the REST API) and writes them to a configurable output target. For Splunk ingestion, two targets are relevant:

Output Target (targettype) Description Splunk Collection Method
f – File System (NDJSON) Writes one JSON event per line to timestamped .json files. Universal/Heavy Forwarder monitor input, or HTTP Event Collector via script
e – Windows Event Log Writes records to the Windows Event Log (Text or JSON body). Splunk Universal Forwarder with WinEventLog input

Recommendation: Use the NDJSON (Splunk) file output (targettype = f, targetfilesystemformat = s) with a Splunk Universal Forwarder monitoring the export directory. This is the simplest, most robust pipeline and matches Splunk’s line?oriented indexing model.


2. Event Schema

Each exported event contains the following fields:

Field Type Description
eventTime string Timestamp of the event (UTC).
tenant string SurePassId tenant (falls back to configured systemname).
username string Username associated with the event.
action string Action performed (e.g., authentication, provisioning).
severity string Event severity level.
eventResultCode int Numeric result/status code.
eventDescription string Human?readable event description.
eventIpV4 string Source IPv4 address.
eventIpV6 string Source IPv6 address.
eventApiKeyName string Name of the API key used.
eventSerialNumber string Token/device serial number.
eventAuthenticationMethod string Authentication method used.
ssoIdentity string External IdP identity (e.g., Azure AD ObjectId, SAML NameID).
userEmail string Email address of the user.

NDJSON (Splunk) layout

When targetfilesystemformat = s, each line is a single self?contained JSON object with no header wrapper — perfect for Splunk’s INDEXED_EXTRACTIONS = json:

{"eventTime":"2025-01-15T18:03:59Z","tenant":"contoso","username":"jdoe","action":"UserAuthentication","severity":"Information","eventResultCode":0,"eventDescription":"Authentication succeeded","eventIpV4":"203.0.113.10","eventIpV6":"","eventApiKeyName":"EventLogSyncKey","eventSerialNumber":"SP-000123","eventAuthenticationMethod":"PushOTP","ssoIdentity":"a1b2c3d4-...","userEmail":"jdoe@contoso.com"}

The alternative structured JSON format (targetfilesystemformat = j) wraps events in a runDate/eventCount/syncEvents array. Avoid it for Splunk — it is not line?delimited and requires custom line?breaking rules. Use NDJSON (s).


3. Configure EventLogSync for Splunk

Set the following in the application app.config (appSettings) or via command line:

<appSettings>
  <add key="Server.UseCommandLine" value="FALSE" />
  <add key="Server.ApiKeyId"     value="YOUR_API_KEY_ID" />
  <add key="Server.ApiKey"       value="YOUR_API_KEY" />
  <add key="Server.RESTEndPoint" value="https://your-server/api" />
  <add key="Server.SystemName"   value="contoso" />

  <!-- Output to file system as NDJSON (one JSON event per line) -->
  <add key="Server.SyncTargetType"             value="f" />
  <add key="Server.SyncTargetFileSystemFormat" value="s" />

  <!-- Continuous polling for near-real-time export -->
  <add key="Server.RunOption"                    value="c" />
  <add key="Server.ContinuousRunWaitTimeSeconds" value="60" />
</appSettings>
  • Files are written to the Export folder next to the executable by default, named SEIM_Export_yyyyMMdd_HHmmss_fff.json.
  • Run EventLogSync as the Windows Service (EventLogSyncService) in continuous mode for a steady feed.

4.1 Create an index (on the indexer / Splunk Cloud)

Create a dedicated index, e.g., surepass_events.

4.2 Configure inputs.conf on the forwarder

On the host running EventLogSync, install the Splunk Universal Forwarder and add a monitor stanza pointing at the export directory:

# $SPLUNK_HOME/etc/system/local/inputs.conf
[monitor://C:\EventLogSync\Export\*.json]
disabled = false
sourcetype = surepass:eventlog
index = surepass_events
crcSalt = <SOURCE>

4.3 Configure props.conf for JSON extraction

On the indexer (or Heavy Forwarder), define the sourcetype so each line is parsed as JSON:

# $SPLUNK_HOME/etc/system/local/props.conf
[surepass:eventlog]
INDEXED_EXTRACTIONS = json
KV_MODE = none
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = "eventTime":"
TIME_FORMAT = %Y-%m-%dT%H:%M:%S%Z
MAX_TIMESTAMP_LOOKAHEAD = 40
TRUNCATE = 100000

TIME_PREFIX/TIME_FORMAT set the event time from the eventTime field instead of the file modification time. Adjust TIME_FORMAT to match your actual eventTime string.

4.4 Restart and verify

Restart the forwarder and indexer, then search:

index=surepass_events sourcetype="surepass:eventlog"
| table _time, tenant, username, action, severity, eventResultCode, eventIpV4, eventAuthenticationMethod, userEmail

5. Approach B – HTTP Event Collector (HEC)

Use HEC when you cannot install a forwarder on the EventLogSync host, or you want to push events directly.

5.1 Enable HEC and create a token

  1. In Splunk: Settings ? Data Inputs ? HTTP Event Collector ? New Token.
  2. Assign the surepass_events index and a sourcetype of surepass:eventlog.
  3. Copy the generated token.

5.2 Forward NDJSON files to HEC

Because EventLogSync already writes one JSON object per line, a small scheduled script can POST each line to the HEC /services/collector/event (or /raw) endpoint. Example (PowerShell):

$hec   = "https://splunk.example.com:8088/services/collector/raw"
$token = "YOUR-HEC-TOKEN"
$dir   = "C:\EventLogSync\Export"

Get-ChildItem "$dir\*.json" | ForEach-Object {
    $body = Get-Content $_.FullName -Raw
    Invoke-RestMethod -Uri $hec -Method Post `
        -Headers @{ Authorization = "Splunk $token" } `
        -Body $body -ContentType "application/json"
    Remove-Item $_.FullName   # remove after successful ingest
}

Using the /raw endpoint with an NDJSON body lets Splunk apply the sourcetype’s INDEXED_EXTRACTIONS = json configuration to each line.


6. Approach C – Windows Event Log (Universal Forwarder)

If you prefer to route through the Windows Event Log:

  1. Configure EventLogSync with Server.SyncTargetType = e and Server.SyncTargetFileSystemFormat = j (JSON message body). Default source name is SEIM_Export, default log is Application.
  2. Configure the Universal Forwarder inputs.conf:
    [WinEventLog://Application]
    disabled = false
    index = surepass_events
    sourcetype = surepass:winevent
    renderXml = false
  3. Filter/extract on the SEIM_Export source and parse the JSON message body with spath:
    index=surepass_events sourcetype="surepass:winevent" SourceName="SEIM_Export"
    | spath input=Message
    | table _time, tenant, username, action, severity, eventResultCode

7. Operational Recommendations

  • Continuous mode: Run the EventLogSyncService Windows Service with Server.RunOption = c and a sensible Server.ContinuousRunWaitTimeSeconds (e.g., 60) for near?real?time ingestion.
  • File cleanup: When forwarding files, delete or rotate processed Export\*.json files after ingestion (the HEC script above removes them on success). crcSalt = <SOURCE> prevents the forwarder from re?reading rotated files with identical headers.
  • Event time: Configure TIME_PREFIX/TIME_FORMAT so Splunk uses eventTime rather than file time for accurate event chronology.
  • Field naming: With INDEXED_EXTRACTIONS = json, fields are auto?extracted using the JSON key names (tenant, username, action, …) — no manual field extraction required.
  • Security: Protect the API key (Server.ApiKey) and restrict permissions on the Export directory and any HEC tokens.
  • CIM mapping: Consider mapping fields to the Splunk Common Information Model Authentication data model (user, src, action, app) via field aliases/calculated fields for use with prebuilt security content.

8. Quick Reference

Setting Recommended value for Splunk
Server.SyncTargetType f (file system)
Server.SyncTargetFileSystemFormat s (NDJSON / Splunk)
Server.RunOption c (continuous)
Server.ContinuousRunWaitTimeSeconds 60
Splunk sourcetype surepass:eventlog
Splunk index surepass_events
Collection method Universal Forwarder monitor input (recommended), HEC, or WinEventLog

For architecture details see EventLogSyncService-Architecture.md. For the Sentinel equivalent see EventLogSync-Sentinel-Ingestion-Guide.md. For product overview see EventLogSync-Product-Datasheet.md and EventLogSync-Product-Summary.md.

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com