Customers experiencing issues with Rublon Log Sync who did not find a solution after reviewing the documentation should send us their configuration file and/or application log file(s) for troubleshooting. However, people often forget to hide sensitive information concerning their credentials and infrastructure.
If you decide to send us your Rublon Log Sync configuration file, environment file, or application log file(s), make sure to remove or redact all sensitive information beforehand.
Sensitive data you should hide before sending us the /etc/rublon-log-sync/config.yaml file:
In the rublon section:
system_token
secret_key
In the global section:
The username and password embedded in proxy_url
Note: If global.secret_source is set to env, the system_token and secret_key fields contain environment variable names instead of the actual secret values. You do not have to redact the variable names from config.yaml.
If you send us the environment file, such as /etc/rublon-log-sync/rublon-log-sync.env, redact the values assigned to the environment variables:
RUBLON_ADMIN_API_SYSTEM_TOKEN
RUBLON_ADMIN_API_SECRET_KEY
Infrastructure information you may want to hide before sending us your configuration file:
The internal proxy hostname and port in global.proxy_url
The SIEM target hostname or IP address and port in sync_jobs[].target
Synchronization job IDs that reveal internal naming conventions
Sensitive operational information you may want to hide before sending us the application log file located at /var/log/rublon-log-sync/rublon-log-sync.log:
Internal hostnames and IP addresses
Network ports
Synchronization job identifiers
Error details that reveal information about your infrastructure
Rublon Log Sync application logs should not contain Rublon Admin API secrets. Nevertheless, always review the files before attaching them to a support ticket.
Helpful Links
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article