Last updated on September 25, 2026
Version 1.1.0 – September 24, 2026
- Added support for Activity Logs from /api/admin/logs/activity. Use type: activity to synchronize these records in JSON or CEF format, with cursor-based pagination, independent per-endpoint checkpoints, and a maximum API lookback of 365 days.
- Changed the Syslog timestamp in partial_syslog and rfc5424 envelopes to use the original event time from createdAt instead of the export time. Timestamps are normalized to UTC and formatted as RFC 3339 with millisecond precision. If createdAt is missing or invalid, the timestamp is set to the Syslog NILVALUE (
-) and the record is still delivered. CEF rt, JSON payloads, and the bare envelope retain their existing formats. - Unified Syslog severity classification for JSON and CEF object records so the same record produces the same Syslog severity and PRI. Updated User.DirectorySync.* rules and added handling for the Phone Log statuses accepted and delivered. Missing, empty, non-text, or unknown events and statuses use the Warning fallback for Audit, Authentication, and Phone Logs. Activity Logs always use Syslog Notice severity, independently of their CEF severity.
- Added stable user and application identifiers to Authentication and Phone Log CEF output: suid for user.id and flexString1, labeled applicationId, for application.id.
- Updated Audit Log CEF mapping: administrator IDs now use suid, and application IDs use flexString1, labeled applicationId. The previous cs1/cs1Label actor ID mapping has been removed. Existing cs2 through cs6 field numbers and meanings are preserved. Missing or unrecognized identifiers are omitted.
- Unified per_page validation across configuration and API requests. The supported range is 15 to 1000; the default remains 100.
- Added handling for organization plan restrictions reported by the Rublon Admin API. Rublon Log Sync stops all synchronization jobs without retrying, exits with code 78, and prevents automatic systemd restart loops.
- Increased the minimum interval to 60 seconds. The default remains 60 seconds.
Before Updating
- Set any interval below 60 to at least 60, or omit the setting to use the default. Set any per_page outside 15 to 1000 to a supported value. Unsupported values fail validation in version 1.1.0.
- Update SIEM rules, dashboards, alerts, and extractors that use Audit Log cs1/cs1Label for actor identification. Use suid for administrators and flexString1 with flexString1Label=applicationId for applications.
- To enable Activity Logs while preserving existing endpoint checkpoints, create a separate synchronization job with a new ID. Adding type: activity to an existing job changes its fingerprint and makes its current checkpoint incompatible.
For the complete upgrade procedure from version 1.0.0 to 1.1.0, including backups, configuration preservation, verification, and rollback, follow Updating Rublon Log Sync.
Version 1.0.0 – July 30, 2026
- Initial release of Rublon Log Sync for synchronizing Audit Logs, Authentication Logs, and Phone Logs from the Rublon Admin API with external SIEM targets