• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Company · Blog · Newsletter · Events · Partner Program

Downloads Support
  • English
Login
Rublon

Rublon

Secure Remote Access

  • Product
    • Regulatory Compliance
    • Use Cases
    • Rublon MFA Reviews
    • Deployment Model
    • What is MFA?
    • User Experience
    • Authentication Methods
    • Rublon Authenticator
    • Rublon App Shield
    • Rublon Identity Bridge
    • Remembered Devices
    • Logs
    • Single Sign-On
    • Access Policies
    • Directory Sync
  • Solutions
    • MFA for Remote Desktop
    • MFA for Remote Access Software
    • MFA for Windows Logon
    • MFA for Linux
    • MFA for On-Premise Active Directory
    • MFA for LDAP
    • MFA for RADIUS
    • MFA for SAML
    • MFA for RemoteApp
    • MFA for Workgroup Accounts
    • MFA for Entra ID
    • MFA for Windows Server Core
  • Customers
  • Industries
    • Financial Services
    • Investment Funds
    • Retail
    • E-Commerce
    • Technology
    • Healthcare
    • Legal
    • Education
    • Government
    • Utilities
    • Manufacturing
  • Pricing
  • Docs
Contact us Free Trial

Rublon Log Sync – Release Notes

July 30, 2026 By Rublon Authors

Last updated on September 25, 2026

Version 1.1.0 – September 24, 2026

  • Added support for Activity Logs from /api/admin/logs/activity. Use type: activity to synchronize these records in JSON or CEF format, with cursor-based pagination, independent per-endpoint checkpoints, and a maximum API lookback of 365 days.
  • Changed the Syslog timestamp in partial_syslog and rfc5424 envelopes to use the original event time from createdAt instead of the export time. Timestamps are normalized to UTC and formatted as RFC 3339 with millisecond precision. If createdAt is missing or invalid, the timestamp is set to the Syslog NILVALUE (-) and the record is still delivered. CEF rt, JSON payloads, and the bare envelope retain their existing formats.
  • Unified Syslog severity classification for JSON and CEF object records so the same record produces the same Syslog severity and PRI. Updated User.DirectorySync.* rules and added handling for the Phone Log statuses accepted and delivered. Missing, empty, non-text, or unknown events and statuses use the Warning fallback for Audit, Authentication, and Phone Logs. Activity Logs always use Syslog Notice severity, independently of their CEF severity.
  • Added stable user and application identifiers to Authentication and Phone Log CEF output: suid for user.id and flexString1, labeled applicationId, for application.id.
  • Updated Audit Log CEF mapping: administrator IDs now use suid, and application IDs use flexString1, labeled applicationId. The previous cs1/cs1Label actor ID mapping has been removed. Existing cs2 through cs6 field numbers and meanings are preserved. Missing or unrecognized identifiers are omitted.
  • Unified per_page validation across configuration and API requests. The supported range is 15 to 1000; the default remains 100.
  • Added handling for organization plan restrictions reported by the Rublon Admin API. Rublon Log Sync stops all synchronization jobs without retrying, exits with code 78, and prevents automatic systemd restart loops.
  • Increased the minimum interval to 60 seconds. The default remains 60 seconds.

Before Updating

  • Set any interval below 60 to at least 60, or omit the setting to use the default. Set any per_page outside 15 to 1000 to a supported value. Unsupported values fail validation in version 1.1.0.
  • Update SIEM rules, dashboards, alerts, and extractors that use Audit Log cs1/cs1Label for actor identification. Use suid for administrators and flexString1 with flexString1Label=applicationId for applications.
  • To enable Activity Logs while preserving existing endpoint checkpoints, create a separate synchronization job with a new ID. Adding type: activity to an existing job changes its fingerprint and makes its current checkpoint incompatible.

For the complete upgrade procedure from version 1.0.0 to 1.1.0, including backups, configuration preservation, verification, and rollback, follow Updating Rublon Log Sync.

Version 1.0.0 – July 30, 2026

  • Initial release of Rublon Log Sync for synchronizing Audit Logs, Authentication Logs, and Phone Logs from the Rublon Admin API with external SIEM targets

Related Posts

Rublon Log Sync

Filed Under: Documentation, Release Notes

Primary Sidebar

Contents

  • Version 1.1.0 – September 24, 2026
    • Before Updating
  • Version 1.0.0 – July 30, 2026
  • Related Posts
Try Rublon MFA for Free
Start your 30-day Rublon MFA Trial to secure your employees using multi-factor authentication.
No Credit Card Required
Rublon 5 star reviews on Gartner Peer Insights

Footer

Product

  • Regulatory Compliance
  • Rublon MFA Reviews
  • Use Cases
  • Deployment Model
  • What is MFA?
  • User Experience
  • Authentication Methods
  • Rublon Authenticator
  • Rublon App Shield
  • Rublon Identity Bridge
  • Remembered Devices
  • Logs
  • Single Sign-On
  • Access Policies
  • Directory Sync

Solutions

  • MFA for Remote Desktop
  • MFA for Windows Logon
  • MFA for Remote Access Software
  • MFA for Linux
  • MFA for On-Premise Active Directory
  • MFA for LDAP
  • MFA for RADIUS
  • MFA for SAML
  • MFA for RemoteApp
  • MFA for Workgroup Accounts
  • MFA for Entra ID
  • MFA for Windows Server Core

Industries

  • Financial Services
  • Investment Funds
  • Retail
  • E-Commerce
  • Technology
  • Healthcare
  • Legal
  • Education
  • Government
  • Utilities
  • Manufacturing

Documentation

  • 2FA for Windows & RDP
  • 2FA for RDS
  • 2FA for RD Gateway
  • 2FA for RD Web Access
  • 2FA for SSH
  • 2FA for OpenVPN
  • 2FA for SonicWall VPN
  • 2FA for Cisco VPN
  • 2FA for Office 365

Support

  • Knowledge Base
  • FAQ
  • System Status

About

  • About Us
  • AI Info
  • Blog
  • Events
  • Careers
  • Co-funded by the European Union
  • Contact Us

  • Facebook
  • GitHub
  • LinkedIn
  • Twitter
  • YouTube

© 2026 Rublon · Imprint · Legal & Privacy · Security