MQTT IoT Broker Integration
Overview
MQTT is a lightweight messaging protocol used in IoT deployments. KYRA MDR monitors MQTT broker logs for detecting unauthorized access and anomalous patterns. Supports Mosquitto, EMQX, and HiveMQ.
Prerequisites
- A KYRA MDR Collector installed and running
- MQTT broker with logging enabled
- Administrative access to the broker configuration
- Network connectivity from the broker to the collector
Configuration
Configure MQTT broker logging:
For Mosquitto:
log_dest sysloglog_type alllog_facility 5connection_messages trueForward via rsyslog:
local5.* @@<collector-ip>:514Restart the broker after configuration changes.
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Connection | Client connect and disconnect | Device monitoring |
| Authentication | Login success and failure | Access control |
| Publish | Message publish events | Data flow monitoring |
| Subscribe | Topic subscription events | Topic access monitoring |
| ACL | Access control list events | Authorization monitoring |
| System | Broker health and status | Infrastructure monitoring |
Troubleshooting
No syslog output: Verify log destination is set to syslog and the facility is configured in rsyslog.
Missing client events: Enable connection_messages true in Mosquitto.
High volume: Log only connection and authentication events in production.
Contact kyra@seekerslab.com for support.