MikroTik RouterOS Syslog
Remote syslog stream of one MikroTik RouterOS edge router: Winbox logins and logouts of six administrators, generic mangle-rule and item edits, DHCP lease assignments for 40 LAN clients and internet UDP packets logged by an input-chain rule, as ECS JSON with the RouterOS message and a constructed BSD-syslog line in event.original. Recurring episodes show an administrator adding, moving, changing and removing a mangle rule within one external Winbox session, leaving no rule behind.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/network-mikrotik-routeros/generator.yml \
--id network-mikrotik-routeros \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| firewall_log | Internet UDP packet logged by an input-chain rule | 83.89% measured share (background 82.5-85.4%) | network |
| dhcp_assigned | Lease assigned to a LAN client | 3.66% measured share (background 3.22-3.80%) | network |
| dhcp_deassigned | Lease of a LAN client deassigned | 3.51% measured share (background 3.08-3.63%) | network |
| login | Administrator logs in via Winbox | 2.01% measured share (background 1.85-2.27%) | authentication |
| logout | Administrator logs out of Winbox | 2.01% measured share (background 1.85-2.27%) | authentication |
| mangle_rule_changed | Mangle rule changed by an administrator | 1.57% measured share (background 1.10-2.04%) | configuration |
| mangle_rule_added | Mangle rule added by an administrator | 1.07% measured share (background 0.95-1.23%) | configuration |
| mangle_rule_removed | Mangle rule removed by an administrator | 1.04% measured share (background 0.93-1.21%) | configuration |
| mangle_rule_moved | Mangle rule moved by an administrator | 1.01% measured share (background 0.78-1.18%) | configuration |
| item_added | Generic item added by an administrator | 0.23% measured share (background 0.17-0.39%) | configuration |
Realism Features
- About 2,600 records per day in UTC. Administrator sessions follow a working-hours curve, about 38 Winbox logins a day plus reconnects, from 3.1 sessions per hour at 07-15 UTC down to 0.27 at 22-05; logged internet UDP packets arrive at about 107 an hour around the clock; DHCP records follow the office day for workstations and laptops and are spread over the day for other devices. Daily and hourly counts vary by up to ±20%; records of one session are seconds to minutes apart, and about 1.5% of seconds hold two or three records.
- Logged packets are unsolicited UDP probes of the WAN address (DNS, NTP, SNMP, IKE, SSDP, SIP) from random sources, one to five packets to one port in quick succession. The rule uses action=log, which records the packet and passes it to the next rule, so no accept/drop outcome is claimed. Each of the 40 DHCP clients joins, stays for a lognormal lease and is deassigned.
- Six administrators are weighted by activity; about 40% of sessions come from the user's own external addresses in 203.0.113.0/24, the rest from the user's internal workstation. About 65% of sessions edit: 60% of those start with work on one mangle rule (added, moved and changed, sometimes removed again as a test rule; added and taken back; or an earlier temporary rule moved, changed and removed as clean-up), followed by random edits with lognormal gaps. Temporary rules stay few without a hard limit; users may hold overlapping sessions and reconnect from the same address minutes after 30% of logouts.
- Background never contains the full chain of one user: an external login followed within 30 minutes by mangle add, move, change and remove. Complete add/move/change/remove sequences from internal addresses and external sessions with any subset of the edits occur in both modes. In default output each episode adds its own records, so counts of chain parts are about one per episode higher than in background alone, more at short intervals.
- RouterOS edit messages carry no session, rule ID, client address or change content, and packet logging is not tied to mangle changes. No complete RouterOS 7 remote frame with this profile was found, so the PRI, header, hostname and topic placement are constructed from RFC 3164 and the manual, with a UTC router clock (PRI 134, local0.info). The DHCP assigned message is inferred by symmetry and the removal wording comes from a RouterOS 6.35rc record. Only Winbox sessions are modelled; login failures, SSH/WebFig/API sessions and filter or NAT rules are out of scope. The ECS mapping follows the vendor Elasticsearch guide for packet fields, the rest is a synthetic choice, and rates are synthetic.
Sample Output
{
"@timestamp": "2026-09-01T08:49:09+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"kind": "event",
"module": "mikrotik",
"dataset": "mikrotik.routeros.syslog",
"category": [
"configuration"
],
"type": [
"change"
],
"action": "mangle_rule_removed",
"original": "<134>Sep 1 08:49:09 mt-edge-01 system,info mangle rule removed by netops"
},
"message": "mangle rule removed by netops",
"observer": {
"hostname": "mt-edge-01",
"ip": "10.30.0.1",
"vendor": "MikroTik",
"product": "RouterOS",
"type": "router"
},
"log": {
"syslog": {
"priority": 134,
"facility": {
"code": 16,
"name": "local0"
},
"severity": {
"code": 6,
"name": "info"
}
}
},
"mikrotik": {
"topics": [
"system",
"info"
]
},
"user": {
"name": "netops"
},
"related": {
"user": [
"netops"
]
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| router_name | mt-edge-01 | Router identity in the syslog header and observer.hostname |
| router_ip | 10.30.0.1 | Management address in observer.ip |
| wan_ip | 192.0.2.10 | WAN address targeted by logged UDP packets |
| wan_gateway_mac | 02:00:5E:10:00:01 | Upstream gateway MAC in packet lines (src-mac) |
| anomaly_mode | true | Include recurring external-session mangle episodes; false produces only the background |
| anomaly_interval_hours | 24 | Episode interval in hours, minimum 4 |
Related Generators
Cisco ASA Firewall
Cisco ASA adaptive security appliance syslog — TCP/UDP/ICMP connection lifecycle, ACL permit/deny decisions, NAT translations, VPN tunnel events, and failover status messages.
Check Point Security Gateway
Check Point Security Gateway SmartLog — 8 software blades including Firewall, IPS, Application Control, URL Filtering, Anti-Bot, Anti-Virus, Threat Emulation, and Identity Awareness.
Network Traffic (Continent-Level Geo)
Network traffic events enriched with continent-level geographic information. Models cross-continent and same-continent flows for both inbound and outbound directions, with realistic allow/deny outcomes based on geographic policy.