Skip to content

MikroTik RouterOS Integration

Overview

MikroTik RouterOS devices provide routing, firewall, and VPN capabilities widely used in SMB environments. KYRA MDR collects MikroTik syslog data for network security monitoring and threat detection. Supports RouterOS 6.x and 7.x.

Prerequisites

  • A KYRA MDR Collector installed and running
  • MikroTik device with administrative access (WinBox or CLI)
  • Network connectivity from the MikroTik to the collector on port 514
  • RouterOS 6.40 or later

Configuration

Configure syslog forwarding via MikroTik CLI:

/system logging action
add name=kyra-mdr target=remote remote=<collector-ip> remote-port=514 \
src-address=0.0.0.0 bsd-syslog=yes syslog-facility=local7
/system logging
add action=kyra-mdr topics=firewall
add action=kyra-mdr topics=system
add action=kyra-mdr topics=error
add action=kyra-mdr topics=warning
add action=kyra-mdr topics=critical

Alternatively, configure via WinBox under System > Logging > Actions and System > Logging > Rules.

Collected Log Types

Log TypeDescriptionSecurity Use
FirewallPacket filter match eventsAccess control, intrusion detection
SystemDevice events and errorsDevice health monitoring
DHCPAddress lease eventsAsset discovery, rogue devices
WirelessWi-Fi client eventsWireless security monitoring
IPsecVPN tunnel eventsRemote access monitoring
UserLogin and authentication eventsAccess auditing

Troubleshooting

No syslog output: MikroTik requires explicit logging rules per topic. Ensure rules are created for the kyra-mdr action with appropriate topics.

Missing firewall logs: Add log=yes log-prefix=FW to individual firewall rules to generate log entries.

BSD syslog format: Ensure bsd-syslog=yes is set on the action. KYRA MDR expects BSD syslog format from MikroTik devices.

Contact kyra@seekerslab.com for support.