Last updated on September 28, 2026
Overview
How Does Rublon Log Sync Work?
Log Sync Diagram

Supported Logs
Phone Log Availability and Event Ordering
Supported Output Formats
Tested SIEM Systems
Before You Start
Create a Rublon MFA Organization
Get the Admin API Credentials
Prepare the SIEM Target
Installing Rublon Log Sync
Install the Package
tar -xzf rublon-log-sync-<version>-linux-<arch>.tar.gz
tar -xzf rublon-log-sync-1.1.0-linux-x86_64.tar.gz
cd rublon-log-sync-<version>-linux-<arch>
sudo bash scripts/install-linux.sh --artifact bin/rublon-log-sync
/opt/rublon-log-sync/bin/rublon-log-sync
File Layout
Configure Rublon Log Sync
/etc/rublon-log-sync/config.yaml
sudo systemctl restart rublon-log-sync
Create the Configuration File
sudo install -o root -g rublon-log-sync -m 0640 \
/etc/rublon-log-sync/config.example.yaml \
/etc/rublon-log-sync/config.yaml
sudo editor /etc/rublon-log-sync/config.yaml
Minimal Configuration Example
log:
debug: false
log_files_count: 7
syslog_enabled: false
global:
secret_source: env
rublon:
api_server: https://core.rublon.net
system_token: "RUBLON_ADMIN_API_SYSTEM_TOKEN"
secret_key: "RUBLON_ADMIN_API_SECRET_KEY"
sync_jobs:
- id: "main"
checkpoint_enabled: true
rublon_endpoints:
- type: audit
- type: authentication
- type: phone
- type: activity
interval: 60
per_page: 100
target:
hostname: "127.0.0.1"
port: 1514
protocol: TCP
format: json
envelope: bare
Store Admin API Credentials in Environment Variables
sudo touch /etc/rublon-log-sync/rublon-log-sync.env
sudo chown root:rublon-log-sync /etc/rublon-log-sync/rublon-log-sync.env
sudo chmod 0640 /etc/rublon-log-sync/rublon-log-sync.env
sudo editor /etc/rublon-log-sync/rublon-log-sync.env
RUBLON_ADMIN_API_SYSTEM_TOKEN=your-system-token
RUBLON_ADMIN_API_SECRET_KEY=your-secret-key
sudo systemctl edit rublon-log-sync
[Service]
EnvironmentFile=/etc/rublon-log-sync/rublon-log-sync.env
sudo systemctl daemon-reload
global:
secret_source: env
rublon:
api_server: https://core.rublon.net
system_token: "RUBLON_ADMIN_API_SYSTEM_TOKEN"
secret_key: "RUBLON_ADMIN_API_SECRET_KEY"
Configuration Sections
Section: log
log:
debug: false
log_files_count: 7
syslog_enabled: false
/var/log/rublon-log-sync/rublon-log-sync.log
Section: global
global:
secret_source: plain
Secret Source
Proxy Server
global:
proxy_url: "proxy.example.com:8080"
http://proxy.example.com:8080
global:
proxy_url: "http://proxy.example.com:8080"
global:
proxy_url: "https://proxy.example.com:8443"
global:
proxy_url: "https://user:password@proxy.example.com:8443"
Section: rublon
rublon:
api_server: https://core.rublon.net
system_token: "RUBLON_ADMIN_API_SYSTEM_TOKEN"
secret_key: "RUBLON_ADMIN_API_SECRET_KEY"
Section: sync_jobs
sync_jobs:
- id: "security-logs"
checkpoint_enabled: true
rublon_endpoints:
- type: audit
- type: authentication
interval: 60
per_page: 100
target:
hostname: "siem.example.com"
port: 1514
protocol: TCP
format: cef
envelope: rfc5424
- id: "phone-logs"
checkpoint_enabled: true
rublon_endpoints:
- type: phone
interval: 300
per_page: 100
target:
hostname: "siem.example.com"
port: 1515
protocol: TCP
format: json
envelope: bare
from_datetime and API Lookback Limits
Section: target
target:
hostname: "siem.example.com"
port: 1514
protocol: TCP
format: cef
envelope: partial_syslog
Payload Envelopes
Syslog Timestamp
Syslog PRI and Severity
Configuration Changes and Checkpoints
Running Rublon Log Sync
Continuous Synchronization
sudo systemctl start rublon-log-sync
sudo systemctl enable rublon-log-sync
One-Shot Synchronization
sudo systemctl stop rublon-log-sync
sudo -u rublon-log-sync \
/opt/rublon-log-sync/bin/rublon-log-sync \
--config-file-path /etc/rublon-log-sync/config.yaml \
--logs-dir-path /var/log/rublon-log-sync \
--checkpoints-dir-path /var/lib/rublon-log-sync/checkpoints \
--once
Verify Log Delivery to Your SIEM

Configuration Source
Runtime Command-Line Options
Managing the Service
systemctl status rublon-log-sync
sudo systemctl start rublon-log-sync
sudo systemctl stop rublon-log-sync
sudo systemctl restart rublon-log-sync
sudo systemctl enable rublon-log-sync
sudo systemctl disable rublon-log-sync
Updating Rublon Log Sync
1. Prepare for the Upgrade
systemctl is-active rublon-log-sync
systemctl is-enabled rublon-log-sync
systemctl cat rublon-log-sync
2. Stop the Service and Back Up the Installation
sudo systemctl stop rublon-log-sync
systemctl is-active rublon-log-sync
sudo install -d -o root -g root -m 0700 /var/backups/rublon-log-sync
sudo mktemp -d /var/backups/rublon-log-sync/1.0.0-before-1.1.0-XXXXXXXX
sudo cp -a /opt/rublon-log-sync "<backup-directory>/opt-rublon-log-sync"
sudo cp -a /etc/rublon-log-sync "<backup-directory>/etc-rublon-log-sync"
sudo cp -a /var/lib/rublon-log-sync "<backup-directory>/var-lib-rublon-log-sync"
sudo cp -a /etc/systemd/system/rublon-log-sync.service \
"<backup-directory>/rublon-log-sync.service"
sudo cp -a /etc/systemd/system/rublon-log-sync.service.d \
"<backup-directory>/rublon-log-sync.service.d"
sudo ls -la "<backup-directory>"
3. Install Version 1.1.0
sudo bash scripts/install-linux.sh --artifact bin/rublon-log-sync
systemctl cat rublon-log-sync
sudo systemctl edit rublon-log-sync
sudo systemctl daemon-reload
4. Restore the Service State and Verify
sudo systemctl start rublon-log-sync
systemctl is-active rublon-log-sync
systemctl is-enabled rublon-log-sync
systemctl status rublon-log-sync
sudo journalctl -u rublon-log-sync -b
sudo grep -F "Rublon Log Sync started: version=1.1.0" \
/var/log/rublon-log-sync/rublon-log-sync.log
Rollback to Version 1.0.0
sudo systemctl stop rublon-log-sync
systemctl is-active rublon-log-sync
RLS_ROLLBACK_SUFFIX="$(date +%Y%m%d-%H%M%S)"
sudo mv /opt/rublon-log-sync \
"/opt/rublon-log-sync.failed-1.1.0-$RLS_ROLLBACK_SUFFIX"
sudo cp -a "<backup-directory>/opt-rublon-log-sync" /opt/rublon-log-sync
sudo cp -a "<backup-directory>/etc-rublon-log-sync/config.example.yaml" \
/etc/rublon-log-sync/config.example.yaml
sudo cp -a "<backup-directory>/rublon-log-sync.service" \
/etc/systemd/system/rublon-log-sync.service
sudo mv /etc/systemd/system/rublon-log-sync.service.d \
"/etc/systemd/system/rublon-log-sync.service.d.failed-1.1.0-$RLS_ROLLBACK_SUFFIX"
sudo cp -a "<backup-directory>/rublon-log-sync.service.d" \
/etc/systemd/system/rublon-log-sync.service.d
sudo cp -a "<backup-directory>/etc-rublon-log-sync/config.yaml" \
/etc/rublon-log-sync/config.yaml
sudo cp -a "<backup-directory>/etc-rublon-log-sync/rublon-log-sync.env" \
/etc/rublon-log-sync/rublon-log-sync.env
sudo mv /var/lib/rublon-log-sync/checkpoints \
"/var/lib/rublon-log-sync/checkpoints.failed-1.1.0-$RLS_ROLLBACK_SUFFIX"
sudo cp -a "<backup-directory>/var-lib-rublon-log-sync/checkpoints" \
/var/lib/rublon-log-sync/checkpoints
sudo systemctl daemon-reload
systemctl cat rublon-log-sync
sudo systemctl start rublon-log-sync
systemctl is-active rublon-log-sync
systemctl is-enabled rublon-log-sync
sudo grep -F "Rublon Log Sync started: version=1.0.0" \
/var/log/rublon-log-sync/rublon-log-sync.log
sudo journalctl -u rublon-log-sync -b
Uninstalling Rublon Log Sync
Optional: Remove Configuration and Stored Data
sudo rm -rf /etc/rublon-log-sync
sudo rm -rf /var/lib/rublon-log-sync
sudo rm -rf /var/log/rublon-log-sync
sudo rm -rf /etc/systemd/system/rublon-log-sync.service.d
sudo systemctl daemon-reload
Application Logs

/var/log/rublon-log-sync/rublon-log-sync.log
journalctl -u rublon-log-sync
journalctl -u rublon-log-sync -f
journalctl -u rublon-log-sync -b
Checkpoints
/var/lib/rublon-log-sync/checkpoints
CEF Mapping
Common Mapping Rules
Timestamp Mapping
2023-07-26T08:40:03.365Z -> 1690360803365
Common Extension Fields
Audit Logs
CEF Event Fields
Audit Log Extension Fields
Audit Severity
Activity Logs
CEF Event Fields
Activity Log Extension Fields
Activity Severity
Authentication Logs
CEF Event Fields
Authentication Log Extension Fields
Authentication Severity
Phone Logs
CEF Event Fields
Phone Log Extension Fields
Phone Severity
Security Best Practices
Troubleshooting
Check the Service Status
systemctl status rublon-log-sync
Check Application Logs
/var/log/rublon-log-sync/rublon-log-sync.log
log:
debug: true
sudo systemctl restart rublon-log-sync
Check systemd Diagnostics
journalctl -u rublon-log-sync -b
journalctl -u rublon-log-sync -f
Organization Plan Restriction (Exit Code 78)
Reset a Failed Service
sudo systemctl reset-failed rublon-log-sync
sudo systemctl start rublon-log-sync