Log Files

Read-only service logs (PHI-scrubbed)

HIPAA Audit Log

Access & action audit trail (HipaaAuditMiddleware) — PHI-masked, archive-aware

Federated Query

Query multiple source PACSes at once (C-FIND fan-out), then retrieve selected studies through this Migration Engine to a target.

Query

Loading…

Dashboard

Bulk DICOM study migration — Q/R discover, C-MOVE pull, C-STORE / STOW-RS push
Projects
0
Migrating
0
Studies Completed
0
Studies Failed
0
License
—
Expires—
Licensed to—
All features included

Active Projects

View all →
Loading...

System

—
—
—
—
—
—
—

Migration Projects

Each project pulls a filtered study set from one source and forwards to one target
Loading...

DICOM Sources

Query sources (C-FIND / C-MOVE pull) and receive sources (C-STORE push-in)
Loading...

DICOM Targets

Destination PACS or VNA we forward to (C-STORE) or STOW-RS
Loading...

Scheduled Migration

Cron-recurring incremental sync — on schedule, discover new studies at a source and enqueue them for migration to a target. The migration runs asynchronously in the normal job pipeline.

Add rule

Filters are non-PHI only (modality + date window). Each fire re-discovers matching studies at the source; already-migrated studies are never re-copied.
Loading...

Q/R Proxy Listeners

Local AE/port pairs that forward inbound C-FIND / C-MOVE / C-ECHO to a configured upstream archive. Hot-reload on save (no service restart needed).
The shared Synthology.Shared.Dicom.ScpProxy library binds each enabled listener on startup AND on hot-reload via IProxyListenerProvider.SpecsChanged (300ms debounce). The per-listener AE Title is also used as the LocalCallingAe when ME opens the outbound association to the upstream — so the upstream's Sender / ACL whitelist must accept this AE.
Loading...

Quality Gates migration_gatekeeper

Pre-forward validation rules. Each gate checks one DICOM tag; outcome is Pass / Warn / Hold / Reject. Applied to every instance just before forwarding.
Loading...

Settings

Local DICOM identity, embedded SCP, concurrency, logging

TLS Certificate

Migration Engine secures data in transit with TLS — DICOM-TLS on the DICOM listeners (HIPAA §164.312(e)(1)) and, where enabled, HTTPS terminated at a reverse proxy. Generate a self-signed TLS certificate + private key (PEM) for this host with the standalone Certificate Builder, then point your TLS settings at the generated .crt / .key (or drop in your own CA-issued certificate). The private key is written on the server and never leaves it — the page shows only the file paths + SHA-256 fingerprint.

Import / Export Configuration

Export the full configuration as a JSON file for backup or migration, or import a previously exported configuration. Secrets (the TLS cert password, the progress-webhook bearer token, and each source / target PACS’s bearer / Basic-auth credentials) are redacted by default and re-applied from the running config on import; tick “Include credentials” to export them passphrase-encrypted for a full cross-host clone.

Sidebar Layout

Drag sidebar sections or items (click & hold for ~200ms, then drag) to reorder them. Right-click any sidebar item to hide it, or right-click a section header to restore hidden items. Your layout is stored per user and follows you across sessions.

SynthGateway Support Agent — Support Connector

The dedicated Synthology Support Connector (a cloudflared service this engine supervises) carries engineer remote-support sessions. It starts only when remote_support is licensed and a tunnel token from Synthology is saved in the connector's own configuration; until then it reads not provisioned and is deliberately left stopped. See Help → Operations → “Remote Support Connector” for where to save the token. The token value is never shown here.
—
—
—
—
—
—

Local DICOM Identity

AE title this engine presents when opening associations to sources/targets.

DICOM Service Limits

Control how many simultaneous DICOM associations are allowed. Outbound sends that exceed the system limit are queued and dispatched as slots become available. Inbound associations are accepted across all listeners combined — per-listener limits in Proxy Listener config still override per-listener.
Maximum simultaneous outbound C-MOVE / C-STORE / C-FIND associations across all sources + targets. Default 10. 0 = unlimited (no queue; legacy behavior).
Maximum simultaneous inbound associations accepted by all SCP listeners combined (embedded receive C-STORE SCP + Q/R Proxy listeners). Default 32. Per-listener max_associations still overrides for listeners that need a different ceiling.
fo-dicom DicomServiceOptions.MaxPDULength. Governs BOTH inbound and outbound association negotiation. 256 KB reduces association round-trips for bulk-migration transfers; pre-association negotiation will clamp if a peer doesn’t support it. 0 = use fo-dicom stock 16384. Restart required.

Embedded C-STORE SCP dicom_scp_receive

Default 11116. Must be reachable from source PACS.

Concurrency & Timing

Studies pulled concurrently. Values > 1 require the parallel_cmove feature.

Progress Webhook progress_webhook

Receive-Mode Defaults

Push-in migrations: when a remote modality C-STOREs studies into our SCP, we batch by silence. Once no new instances have arrived for a study for Quiescence Window seconds, the study auto-flips to the forward queue. Override per-source on the Sources page.
Applied to every receive-kind source in addition to its per-source whitelist. Empty = rely on per-source lists only.

Auto-merge Studies auto_merge_studies

Per-project override available on each Receive-kind project's detail page.

Web & Logging

Restart the service for Web Host / Web Port changes to take effect. Changes to the Embedded C-STORE SCP (Enabled, Listen Port, Receiver AE Title) apply live on save — the receive listener gracefully drains in-flight associations and rebinds, no restart needed.

Authentication & HIPAA

Default on — migration.db records Patient IDs and study UIDs.

SynthInSight Analytics Archive

Archive migration-event metadata to gzipped NDJSON before it is pruned (feed SynthInSight). On by default.
At the fixed 7-day operational window, event-metadata rows older than 7 days are pruned from the hot database. When this is on, those rows are first written to date-partitioned gzipped NDJSON under the archive root below — preserving all-time history off the hot DB for the SynthInSight analytics product. Best-effort: an archive error is logged and the prune still proceeds.
Directory the gzipped-NDJSON archive is written to — point this at a location SynthInSight can read (a shared path or mounted volume). The link to SynthInSight is this shared filesystem path, not a network call. Leave empty for the default <dataDir>/analytics-archive.

License

Install or review the Synthology license file

Current License

—
—
—
—
—
—
—
—
—

What this license enables

📥 Install or Replace License

Activate with a one-time token (online), or install a .lic file directly for air-gapped / offline sites — both on the activation page.

Activate or replace license →

System Status

Health, SCP listener, association counters

Runtime

Loading...

SCP Association Counters

Loading...