As the Service Provider, we've implemented AbstractSAMLObserver. This has allowed us to see and log the actual claim as it comes into our application.
The problem is that every authentication from the identity provider results in OnSAMLResponseReceived being called dozens if not hundreds of times within a second. The SAMLResponse received is identical in all calls.
Is this the way it is supposed to work? It's very noisy within our log system and making real issues hard to identify.