Log Files
Read-only service logs (PHI-scrubbed)
HIPAA Audit Log
Access & action audit trail (HipaaAuditMiddleware) — PHI-masked, archive-aware
Federated Query
Query multiple source PACSes at once (C-FIND fan-out), then retrieve selected studies through this Migration Engine to a target.
Query
Loading…
Dashboard
Bulk DICOM study migration — Q/R discover, C-MOVE pull, C-STORE / STOW-RS push
Projects
0
Migrating
0
Studies Completed
0
Studies Failed
0
License
—
Active Projects
View all →Loading...
System
—
—
———
—
—
Migration Projects
Each project pulls a filtered study set from one source and forwards to one target
Loading...
DICOM Sources
Query sources (C-FIND / C-MOVE pull) and receive sources (C-STORE push-in)
Loading...
DICOM Targets
Destination PACS or VNA we forward to (C-STORE) or STOW-RS
Loading...
Scheduled Migration
Cron-recurring incremental sync — on schedule, discover new studies at a source and enqueue them for migration to a target. The migration runs asynchronously in the normal job pipeline.
Add rule
Filters are non-PHI only (modality + date window). Each fire re-discovers matching studies at the source; already-migrated studies are never re-copied.
Loading...
Q/R Proxy Listeners
Local AE/port pairs that forward inbound C-FIND / C-MOVE / C-ECHO to a configured upstream archive. Hot-reload on save (no service restart needed).
The
shared
Synthology.Shared.Dicom.ScpProxy library
binds each enabled listener on startup AND on hot-reload via
IProxyListenerProvider.SpecsChanged (300ms debounce).
The per-listener AE Title is also used as the LocalCallingAe
when ME opens the outbound association to the upstream — so the
upstream's Sender / ACL whitelist must accept this AE.
Loading...
Quality Gates migration_gatekeeper
Pre-forward validation rules. Each gate checks one DICOM tag; outcome is Pass / Warn / Hold / Reject. Applied to every instance just before forwarding.
Loading...
Settings
Local DICOM identity, embedded SCP, concurrency, logging
TLS Certificate
Migration Engine secures data in transit with TLS — DICOM-TLS on the DICOM listeners
(HIPAA §164.312(e)(1)) and, where enabled, HTTPS terminated at a reverse proxy. Generate a
self-signed TLS certificate + private key (PEM) for this host with the standalone
Certificate Builder, then point
your TLS settings at the generated
.crt / .key (or drop in your own
CA-issued certificate). The private key is written on the server and never leaves it — the
page shows only the file paths + SHA-256 fingerprint.
Import / Export Configuration
Export the full configuration as a JSON file for backup or migration, or import a
previously exported configuration. Secrets (the TLS cert password, the progress-webhook
bearer token, and each source / target PACS’s bearer / Basic-auth credentials) are
redacted by default and re-applied from the running config on import; tick
“Include credentials” to export them passphrase-encrypted for a full
cross-host clone.
Sidebar Layout
Drag sidebar sections or items (click & hold for ~200ms, then drag) to reorder them. Right-click any sidebar item to hide it, or right-click a section header to restore hidden items. Your layout is stored per user and follows you across sessions.
SynthGateway Support Agent — Support Connector
The dedicated Synthology Support Connector (a
cloudflared service this engine supervises)
carries engineer remote-support sessions. It starts only when remote_support is licensed
and a tunnel token from Synthology is saved in the connector's own configuration; until then it
reads not provisioned and is deliberately left stopped. See Help → Operations →
“Remote Support Connector” for where to save the token. The token value is never shown here.
—
—
—
—
—
—
Local DICOM Identity
AE title this engine presents when opening associations to sources/targets.
DICOM Service Limits
Control how many simultaneous DICOM associations are allowed.
Outbound sends that exceed the system limit are queued and
dispatched as slots become available. Inbound associations
are accepted across all listeners combined — per-listener
limits in Proxy Listener config still override per-listener.
Maximum simultaneous outbound C-MOVE / C-STORE / C-FIND
associations across all sources + targets. Default 10.
0 = unlimited (no queue; legacy behavior).
Maximum simultaneous inbound associations accepted by all
SCP listeners combined (embedded receive C-STORE SCP +
Q/R Proxy listeners). Default 32. Per-listener
max_associations still overrides for listeners
that need a different ceiling.
fo-dicom
DicomServiceOptions.MaxPDULength. Governs BOTH inbound and outbound association negotiation. 256 KB reduces association round-trips for bulk-migration transfers; pre-association negotiation will clamp if a peer doesn’t support it. 0 = use fo-dicom stock 16384. Restart required.Embedded C-STORE SCP dicom_scp_receive
Default 11116. Must be reachable from source PACS.
Concurrency & Timing
Studies pulled concurrently. Values > 1 require the
parallel_cmove feature.Progress Webhook progress_webhook
Receive-Mode Defaults
Push-in migrations: when a remote modality C-STOREs studies into our SCP,
we batch by silence. Once no new instances have arrived for a study for
Quiescence Window seconds, the study auto-flips to the forward queue.
Override per-source on the Sources page.
Applied to every receive-kind source in addition to its per-source whitelist. Empty = rely on per-source lists only.
Auto-merge Studies auto_merge_studies
Per-project override available on each Receive-kind project's detail page.
Web & Logging
Restart the service for Web Host / Web Port changes to take effect. Changes to the Embedded C-STORE SCP (Enabled, Listen Port, Receiver AE Title) apply live on save — the receive listener gracefully drains in-flight associations and rebinds, no restart needed.
Authentication & HIPAA
Default on — migration.db records Patient IDs and study UIDs.
SynthInSight Analytics Archive
Archive migration-event metadata to gzipped NDJSON before it is pruned (feed SynthInSight). On by default.
At the fixed 7-day operational window, event-metadata rows older than 7 days are pruned from the hot database. When this is on, those rows are first written to date-partitioned gzipped NDJSON under the archive root below — preserving all-time history off the hot DB for the SynthInSight analytics product. Best-effort: an archive error is logged and the prune still proceeds.
Directory the gzipped-NDJSON archive is written to — point this at a location SynthInSight can read (a shared path or mounted volume). The link to SynthInSight is this shared filesystem path, not a network call. Leave empty for the default
<dataDir>/analytics-archive.License
Install or review the Synthology license file
Current License
—
—
—
—
—
—
—
—
—
What this license enables
📥 Install or Replace License
Activate with a one-time token (online), or install a .lic file directly for
air-gapped / offline sites — both on the activation page.
System Status
Health, SCP listener, association counters
Runtime
Loading...
SCP Association Counters
Loading...