본문으로 건너뛰기

MQTT IoT Broker Integration

Overview

MQTT is a lightweight messaging protocol used in IoT deployments. KYRA MDR monitors MQTT broker logs for detecting unauthorized access and anomalous patterns. Supports Mosquitto, EMQX, and HiveMQ.

Prerequisites

  • A KYRA MDR Collector installed and running
  • MQTT broker with logging enabled
  • Administrative access to the broker configuration
  • Network connectivity from the broker to the collector

Configuration

Configure MQTT broker logging:

For Mosquitto:

mosquitto.conf
log_dest syslog
log_type all
log_facility 5
connection_messages true

Forward via rsyslog:

/etc/rsyslog.d/mqtt.conf
local5.* @@<collector-ip>:514

Restart the broker after configuration changes.

Collected Log Types

Log TypeDescriptionSecurity Use
ConnectionClient connect and disconnectDevice monitoring
AuthenticationLogin success and failureAccess control
PublishMessage publish eventsData flow monitoring
SubscribeTopic subscription eventsTopic access monitoring
ACLAccess control list eventsAuthorization monitoring
SystemBroker health and statusInfrastructure monitoring

Troubleshooting

No syslog output: Verify log destination is set to syslog and the facility is configured in rsyslog.

Missing client events: Enable connection_messages true in Mosquitto.

High volume: Log only connection and authentication events in production.

Contact kyra@seekerslab.com for support.