LINUXOR.SK ... open source notes ...

Balabit - message-queue-client.conf of the SCB

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring

The one include file of the appliance's syslog-ng configuration that I kept: a source on localhost TCP 56456 and a log path without a destination, so whatever arrives there is read and thrown away.

ItemValue
Path/etc/syslog-ng/conf.d/message-queue-client.conf, core firmware
Read by@include "/etc/syslog-ng/conf.d/*.conf" in syslog-ng.conf of the SCB (site 1)
ClusterKept with the site 1 syslog-ng.conf; the support bundle of the site 2 cluster of 2018-09-17 contains the same file, line for line
Softwaresyslog-ng 3.8 as in the main file; the include has no version line of its own

The file

ini
# network() source expects log message conforming RFC3164
source s_message_queue_client {
    network(ip(localhost) port(56456) transport(tcp));
};

# This is basically a /dev/null like log path, whatever gets read from the source goes nowhere,
# it will not even be kept in memory.
log {
    source(s_message_queue_client);
};
LineWhat it does
network(ip(localhost) port(56456) transport(tcp))Listens on the loopback address only, TCP 56456, and expects BSD syslog messages (RFC 3164), as the vendor's comment says
log { source(...); };A log path with a source and no destination: the messages are accepted and discarded

What writes to port 56456 the file does not say. The exported config.xml of the site 2 cluster has the answer as far as it goes: its <notifier> element sets <rabbitmq enabled="no"/> and <syslog><port>56456</port></syslog>. As I read it, the appliance's notifier can publish events to a message queue (RabbitMQ) or, when that is off, to syslog on this port, and this include makes sure those notifications neither pile up nor reach the central syslog server. Neither the design nor my notes mention the notifier, so this is my reading of two files, not something I configured.

← solutionz