Learn how Rublon Log Sync can automatically retrieve Rublon MFA audit, authentication, and phone logs and send them to a Security Information and Event Management (SIEM) system for centralized monitoring, correlation, and investigation.
Scenario
An organization uses Rublon MFA to protect access to applications, servers, workstations, VPNs, and other parts of its IT infrastructure. Rublon MFA records authentication attempts, administrative actions, and events related to phone-based authentication methods.
The organization’s security team uses a SIEM system to collect and analyze security events from across the environment. To gain a complete view of identity and access activity, the team also wants to include Rublon MFA logs in its centralized monitoring and incident investigation workflows.
Challenge
Rublon MFA logs provide important information about successful, denied, and bypassed authentication attempts, administrative changes, and the use of phone-based authentication methods. However, reviewing these logs separately from other security telemetry makes it more difficult to correlate events across systems and identify suspicious activity.
Manual log exports are not suitable for continuous security monitoring. Building and maintaining a custom integration with the Rublon Admin API also requires development work, secure credential handling, pagination, format conversion, delivery logic, and synchronization state management.
The organization needs a reliable way to continuously transfer Rublon MFA logs to its SIEM system without developing a dedicated log collection application.
Solution
Deploy Rublon Log Sync on a Linux server to retrieve logs from the Rublon Admin API and forward them to the organization’s SIEM system.
Rublon Log Sync can synchronize Audit Logs, Authentication Logs, and Phone Logs. It sends each record over TCP in compact JSON or Common Event Format (CEF), allowing the organization to select the format supported by its SIEM platform. Messages can be sent without a syslog envelope, with a shortened syslog prefix, or with a complete RFC 5424 syslog envelope.
Administrators can configure multiple independent synchronization jobs for different log types, destinations, time ranges, and polling intervals. Checkpoints record synchronization progress so that subsequent cycles can continue from the saved position.
After the logs reach the SIEM system, the security team can correlate Rublon MFA events with information from firewalls, endpoints, directory services, VPNs, applications, and other security tools.

Benefits
- Centralized MFA visibility: Analyze Rublon MFA authentication attempts, administrative actions, and phone-related events alongside other security telemetry.
- Faster incident investigation: Correlate identity and access events with activity recorded by endpoints, applications, network devices, and directory services.
- SIEM-compatible output: Send logs in compact JSON or CEF format with a bare, partial syslog, or RFC 5424 envelope.
- Continuous synchronization: Automatically retrieve new records according to configurable polling intervals instead of relying on manual exports.
- Reliable synchronization progress: Use checkpoints to resume synchronization from the saved position and reduce unnecessary reprocessing of previously retrieved records.
- Flexible log routing: Configure multiple synchronization jobs with separate endpoints, SIEM targets, schedules, and initial time ranges.