MikroTik RouterOS Integration
Overview
MikroTik RouterOS devices provide routing, firewall, and VPN capabilities widely used in SMB environments. KYRA MDR collects MikroTik syslog data for network security monitoring and threat detection. Supports RouterOS 6.x and 7.x.
Prerequisites
- A KYRA MDR Collector installed and running
- MikroTik device with administrative access (WinBox or CLI)
- Network connectivity from the MikroTik to the collector on port 514
- RouterOS 6.40 or later
Configuration
Configure syslog forwarding via MikroTik CLI:
/system logging actionadd name=kyra-mdr target=remote remote=<collector-ip> remote-port=514 \ src-address=0.0.0.0 bsd-syslog=yes syslog-facility=local7
/system loggingadd action=kyra-mdr topics=firewalladd action=kyra-mdr topics=systemadd action=kyra-mdr topics=erroradd action=kyra-mdr topics=warningadd action=kyra-mdr topics=criticalAlternatively, configure via WinBox under System > Logging > Actions and System > Logging > Rules.
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Firewall | Packet filter match events | Access control, intrusion detection |
| System | Device events and errors | Device health monitoring |
| DHCP | Address lease events | Asset discovery, rogue devices |
| Wireless | Wi-Fi client events | Wireless security monitoring |
| IPsec | VPN tunnel events | Remote access monitoring |
| User | Login and authentication events | Access auditing |
Troubleshooting
No syslog output: MikroTik requires explicit logging rules per topic. Ensure rules are created for the kyra-mdr action with appropriate topics.
Missing firewall logs: Add log=yes log-prefix=FW to individual firewall rules to generate log entries.
BSD syslog format: Ensure bsd-syslog=yes is set on the action. KYRA MDR expects BSD syslog format from MikroTik devices.
Contact kyra@seekerslab.com for support.