Balabit - message-queue-client.conf of the SCB
Balabit SCB Solution · Config document · referenced from Basic settings, logging and monitoring
The one include file of the appliance's syslog-ng configuration that I kept: a source on localhost TCP 56456 and a log path without a destination, so whatever arrives there is read and thrown away.
| Item | Value |
|---|---|
| Path | /etc/syslog-ng/conf.d/message-queue-client.conf, core firmware |
| Read by | @include "/etc/syslog-ng/conf.d/*.conf" in syslog-ng.conf of the SCB (site 1) |
| Cluster | Kept with the site 1 syslog-ng.conf; the support bundle of the site 2 cluster of 2018-09-17 contains the same file, line for line |
| Software | syslog-ng 3.8 as in the main file; the include has no version line of its own |
The file
# network() source expects log message conforming RFC3164 source s_message_queue_client { network(ip(localhost) port(56456) transport(tcp)); }; # This is basically a /dev/null like log path, whatever gets read from the source goes nowhere, # it will not even be kept in memory. log { source(s_message_queue_client); };
| Line | What it does |
|---|---|
network(ip(localhost) port(56456) transport(tcp)) | Listens on the loopback address only, TCP 56456, and expects BSD syslog messages (RFC 3164), as the vendor's comment says |
log { source(...); }; | A log path with a source and no destination: the messages are accepted and discarded |
What writes to port 56456 the file does not say. The exported config.xml of the site 2 cluster has the answer as far as it goes: its <notifier> element sets <rabbitmq enabled="no"/> and <syslog><port>56456</port></syslog>. As I read it, the appliance's notifier can publish events to a message queue (RabbitMQ) or, when that is off, to syslog on this port, and this include makes sure those notifications neither pile up nor reach the central syslog server. Neither the design nor my notes mention the notifier, so this is my reading of two files, not something I configured.