Community discussions

MikroTik App

Search found 3684 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 13
by Jotne
Wed Aug 03, 2022 12:30 pm
Forum: Useful user articles
Topic: Configuration to block users that tries to access router on non open port(s)
Replies: 86
Views: 25885

Re: 📌 Configuration to block users that tries to access router on non open port(s)

Lets say that you have a web server (443) and RDP (3389) open to all internett. If some one with bad intention has a script that tests various ports, and if open ports are found trying to breake inn, this script for sure helps. When the hackers script test port 10000 for any reason, he will be block...
by Jotne
Mon Aug 01, 2022 8:36 am
Forum: Beginner Basics
Topic: Graphing - Store to disk / disk wear.
Replies: 7
Views: 1974

Re: Graphing - Store to disk / disk wear.

Or any external tools Syslog/SNMP

See my signature
by Jotne
Mon Aug 01, 2022 8:34 am
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

Then start responding to what you are asked for to supply.
by Jotne
Mon Aug 01, 2022 12:02 am
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

You do not get it????

To find a specific User in the User Profile, you need to have some search criteria that you fail to post.
Time to close thread.
by Jotne
Sun Jul 31, 2022 10:03 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) 💾 🛠 💻 📊

No I understand what you asks for :) I do use a simple setup with one pool pr each vlan. What I would say most do. IP you see after the scope is the host IP. The reason for having it there is that if you have two routers with both have same pool name (default setup), Splunk would mix each scope toge...
by Jotne
Sat Jul 30, 2022 9:33 pm
Forum: Announcements
Topic: v7.4 [stable] is released!
Replies: 224
Views: 56567

Re: v7.4 [stable] is released!

@7sergeynazarov7
Contact MikroTik and they will help out.
support@mikrotik.com
by Jotne
Sat Jul 30, 2022 9:30 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) 💾 🛠 💻 📊

1. I do see you get Duplicate Values under host. This may be that you did change name on one device ore have multiple host with same name. Install Lookup Editor in Splunk if you do not already have done. Got to Apps -> Lookup Editor, select device_kvstore and open it. Remove the duplicate line. 2. T...
by Jotne
Thu Jul 28, 2022 6:08 am
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

Its you that search for a solution, but you can not tell me what you want. I do not ask for help.
More strange request I have never seen.............
by Jotne
Wed Jul 27, 2022 11:12 pm
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

What do you not understand.

You like to find a USER.....
What are the criteria for finding the one, 1 user from all the other users????????????????????
Hi is big/fat/thin green/red ......
by Jotne
Wed Jul 27, 2022 8:28 pm
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

To find something you need some to search for. Like comments, sittings, part of name.

I would like to find the user that has x y z.......
by Jotne
Wed Jul 27, 2022 2:45 pm
Forum: Useful user articles
Topic: Configuration to block users that tries to access router on non open port(s)
Replies: 86
Views: 25885

Re: 📌 Configuration to block users that tries to access router on non open port(s)

Are this true?
This needs to be the last two filter rules.
by Jotne
Wed Jul 27, 2022 11:52 am
Forum: Announcements
Topic: not strictly related to v7.5beta
Replies: 30
Views: 5399

not strictly related to v7.5beta

Please use resource on getting a long term 7.x version. As it is now there are new 7.x train every week, but not may bug fixes for current train.
Latest releases that should be followed up
7.1.5 - 22 Mars 2022 (maybe 7.1.6 LT next)
7.2.3 - 2 May 2022
7.3.1 - 9 Juni 2022
7.4.0 - 19 Juli 2022
by Jotne
Wed Jul 27, 2022 8:11 am
Forum: Useful user articles
Topic: Configuration to block users that tries to access router on non open port(s)
Replies: 86
Views: 25885

Re: 📌 Configuration to block users that tries to access router on non open port(s)

If you add a nat rule to port 443 (https), you do not need an explicit filter rule, but I do have it. And if you have a filter rule, it must be before the rule that starts to block stuff. Filter rule: add action=accept chain=forward dst-port=443 in-interface=ether1 log=yes log-prefix=FI_A_HTTPS prot...
by Jotne
Wed Jul 27, 2022 8:01 am
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

And then I still do not understand what you need. Gives up.
by Jotne
Tue Jul 26, 2022 11:30 pm
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

This is just simple basic MiroTik scripting. If that is what you need, you should start learning scripting before you make scripts. You can past this to terminal ans see whats result of it # Get all ID for all user and loop trough one and one :foreach id in=[/ip hotspot user profile find] do={ # Get...
by Jotne
Tue Jul 26, 2022 9:50 pm
Forum: Announcements
Topic: v7.4 [stable] is released!
Replies: 224
Views: 56567

Re: v7.4 [stable] is released!

anyway where's the new testing release?
As usual, under development.
Or MT workers may have vacation.
by Jotne
Tue Jul 26, 2022 9:47 pm
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

How do you like to find a single user, what is the unique input you have to find the user.

Example. You have a dns name like forum,mikrotik.com. This can be used to find one unique IP 159.148.147.239
Also what do you like to do with that user when its found.
by Jotne
Sun Jul 24, 2022 6:45 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: 📌 Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) 💾 🛠 💻 📊

I have tested it on bot 7.2.3 and 7.4 without any problem. What do you see when you cut and past this to terminal. { :local CmdHistory true # Get detailed command history RouterOS >= v7 # ---------------------------------- :if ([:tonum [:pick [/system resource get version] 0 1]] > 6 and $CmdHistory)...
by Jotne
Sun Jul 24, 2022 5:59 pm
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

I have given up. Does not understand what you want. Every time I ask, you reply with more or less the same.
Since no other has answered, I gess no other understand as well.
by Jotne
Sun Jul 24, 2022 10:15 am
Forum: Scripting
Topic: Create directory on remote FTP server
Replies: 4
Views: 2518

Re: Create directory on remote FTP server

Or you can use an FTP server that automatically make the directory if its missing and the user has create directory permission.
by Jotne
Sun Jul 24, 2022 9:12 am
Forum: Scripting
Topic: Hotspot cookie/active problem
Replies: 17
Views: 3823

Re: Hotspot cookie/active problem

From the manual Reserved variable names All built in RouterOS properties are reserved variables. Variables which will be defined the same as the RouterOS built in properties can cause errors. To avoid such errors, use custom designations. For example, following script will not work: { :local type &q...
by Jotne
Sun Jul 24, 2022 9:05 am
Forum: Scripting
Topic: Updating certificate store requires very strange permissions
Replies: 1
Views: 612

Re: Updating certificate store requires very strange permissions

Not an answer to your question, but som script cleaning. Removed outer {} that is not needed. Removed all ; at end of line. Only needed between multiple commands on same line. You did have it on some line, not all. Removed :set verifySSL "yes". You can set ut while declare the variable. :d...
by Jotne
Sat Jul 23, 2022 12:46 am
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

What is the previous command?

Post a flow diagram or complete code. This is very unclear and you only repeat your self.
by Jotne
Fri Jul 22, 2022 7:26 pm
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

So you want to find User Profile with name XXXX and then change its name to something else?
by Jotne
Fri Jul 22, 2022 2:12 pm
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

Still unclear. The command you have now, will give you the mac-cookie-timeout for the user-profile XXXX What name do you like ( the name XXXX ?) to be stored where. I have a USER PROFILE with the name "XXXX" and I want that name VVVV<-------------| that here points to "XXXX", tha...
by Jotne
Fri Jul 22, 2022 10:43 am
Forum: Scripting
Topic: USER PROFILE [SOLVED]
Replies: 35
Views: 4730

Re: USER PROFILE [SOLVED]

Copy what to where?
by Jotne
Thu Jul 21, 2022 10:53 pm
Forum: Beginner Basics
Topic: Extract config from backup file [SOLVED]
Replies: 9
Views: 3869

Re: Extract config from backup file [SOLVED]

Simply open the backup with "notepad"
I have never thought about that :)
Notepad++ is a must have tool.
by Jotne
Wed Jul 20, 2022 11:34 pm
Forum: Scripting
Topic: Policies needed for automatic upgrade
Replies: 3
Views: 1235

Re: Policies needed for automatic upgrade

If you for some reason need to auto upgrade using a script, them make the script check an external web server if a flag is set. Flag says no, do not upgrade, if flag says yes, then script can upgrade. This to make sure it does not upgrade before you let it do it. Before you upgrade, test all your di...
by Jotne
Wed Jul 20, 2022 3:47 pm
Forum: Announcements
Topic: v7.4 [stable] is released!
Replies: 224
Views: 56567

Re: v7.4 [stable] is released!

I would like to see 7.3.2. As it is know it seems to be a rush to release new main version.
Need a 7.x long term version.
by Jotne
Wed Jul 20, 2022 10:22 am
Forum: General
Topic: IPv6 and Cloud Issues [SOLVED]
Replies: 5
Views: 2369

Re: IPv6 and Cloud Issues [SOLVED]

Did enter same situation. Someone was not able to go to my webserver and after some investigation we see that he tried IPv6, that I have disabled 2 years ago. A lookup of DNS to google and other did show both IPv4 and IPv6 ip for my Cloud name. Just disable DDNS in cloud and enable it again did reso...
by Jotne
Wed Jul 20, 2022 8:47 am
Forum: Scripting
Topic: Removing ip addresses in a list based on another
Replies: 13
Views: 4399

Re: Removing ip addresses in a list based on another

You can not easily read the creation time "jul/19/2022 22:37:42" and compare with something. This has been discussed for many many years. I did hope with v7.x that MikroTik would use a standard time format. For example EPOCH time. Here are some help to do that. https://forum.mikrotik.com/...
by Jotne
Tue Jul 19, 2022 11:38 pm
Forum: Scripting
Topic: Removing ip addresses in a list based on another
Replies: 13
Views: 4399

Re: Removing ip addresses in a list based on another

This sript moves static IP that has more than 100 days of no use. You can see have I calculate days to get an idea on how to use it. # Created Jotne 2021 v1.0 # Remove all static DHCP and corresponding DNS leases more than 100 week old :local counter 0 /ip dhcp-server lease :foreach id in=[find wher...
by Jotne
Tue Jul 19, 2022 7:35 am
Forum: Scripting
Topic: Removing ip addresses in a list based on another
Replies: 13
Views: 4399

Re: Removing ip addresses in a list based on another

Here is a script that I do use. If an IP are found in access list "Whitelist_IP" and also fond in access list "Block_list", remove it from "Block_list" Then send a pushbullet message to my phone. (Can be any type of message, logging, email, telegram etc) # Remove ip fro...
by Jotne
Sun Jul 17, 2022 10:40 am
Forum: General
Topic: To MT: Keep accounting (v7.x)
Replies: 50
Views: 17421

Re: To MT: Keep accounting (v7.x)

Have you looked at Kid control? For me it gives more or less the same as I did get from accounting.
by Jotne
Sat Jul 16, 2022 11:38 pm
Forum: Scripting
Topic: Custom OID
Replies: 1
Views: 596

Re: Custom OID

As far as I know, you can not make custom OID. I do use Syslog to send whatever data you like to monitor from the Router to Splunk instead of using SNMP
by Jotne
Sat Jul 16, 2022 10:21 am
Forum: Wireless Networking
Topic: Wifi 6 Date
Replies: 1
Views: 572

Re: Wifi 6 Date

Do a search before asking.

viewtopic.php?t=157059
by Jotne
Fri Jul 15, 2022 3:27 pm
Forum: Beginner Basics
Topic: Mikrotik router Bridge ports
Replies: 4
Views: 1871

Re: Mikrotik router Bridge ports

Adding ports to a Bridge, just make them able to talk together. Bridge will act just a switch and switch data from one port to another port. As akakua points out, you need to look at bonding. That will make multiple interface act as one big line. But there are various types of bonding, look at linke...
by Jotne
Fri Jul 15, 2022 8:10 am
Forum: Scripting
Topic: Netwatch Notification Help
Replies: 3
Views: 786

Re: Netwatch Notification Help

Save up time in an global variable, then when going down calculate the difference in time.

Or you can use Splunk like I do and see it graphically:
viewtopic.php?p=888800#p888800
by Jotne
Mon Jul 11, 2022 1:05 pm
Forum: General
Topic: Upload file to Windows FTP
Replies: 11
Views: 1657

Re: Upload file to Windows FTP

If your try to upload a file to a FTP server and the file do already exist (on the FTP server), you will get an error if user do not have delete access.
by Jotne
Sat Jul 09, 2022 10:47 am
Forum: Beginner Basics
Topic: Script cloud-backup notification [SOLVED]
Replies: 17
Views: 2371

Re: Script cloud-backup notification [SOLVED]

@k6ccc
Instead of hardcode subject name, you can make a dynamic name, based on serial, identity etc.

See backup script to gmail here:
viewtopic.php?t=183631
by Jotne
Wed Jul 06, 2022 11:35 am
Forum: Scripting
Topic: Script global variable get from SNMP OID
Replies: 4
Views: 4190

Re: Script global variable get from SNMP OID

I was looking at this as well.
My goal was to read a global variable from the router using SNMP directly, but there seems to not be any OID to do that.
And even better if you could set a global variable on the router using write SNMP.
by Jotne
Tue Jul 05, 2022 7:40 am
Forum: Scripting
Topic: Reset uptime only not all counters
Replies: 2
Views: 687

Re: Reset uptime only not all counters

Why?

You should add picture to the post. Edit post and click Attachments.
by Jotne
Mon Jul 04, 2022 8:27 pm
Forum: Scripting
Topic: how to get numbers in message [SOLVED]
Replies: 5
Views: 1273

Re: how to get numbers in message [SOLVED]

Look at this post:
viewtopic.php?t=102375
It shows how to loop through a text string from start to end (len of string)

Then you need to make some logic to extract one and one number.
by Jotne
Mon Jul 04, 2022 11:08 am
Forum: General
Topic: Disable port over snmp
Replies: 10
Views: 4541

Re: Disable port over snmp

Working on hAP ac^2 :) You need to specify i for integer. And 1 is up and 2 is down. snmpwalk -v2c -c public 192.168.1.14 1.3.6.1.2.1.2.2.1.7 IF-MIB::ifAdminStatus.1 = INTEGER: up(1) IF-MIB::ifAdminStatus.2 = INTEGER: up(1) IF-MIB::ifAdminStatus.3 = INTEGER: up(1) IF-MIB::ifAdminStatus.4 = INTEGER: ...
by Jotne
Mon Jul 04, 2022 8:08 am
Forum: General
Topic: Virus attack on the router
Replies: 5
Views: 1046

Re: Virus attack on the router

but this computer is the only one in the router's network, I connect to it via RDP. Since this is your computer, reinstall it. You do not now what other problems you will get with it, since its already are infected. To reach inn to your network wit RDP, you should use VPN from your external device....
by Jotne
Sun Jul 03, 2022 4:51 pm
Forum: Scripting
Topic: how to dynamic block unwanted ips?
Replies: 7
Views: 2231

Re: how to dynamic block unwanted ips?

You need to open all port you like to use in port knocking on the front router to reach your MikroTik router.
by Jotne
Sun Jul 03, 2022 12:18 pm
Forum: General
Topic: Zerotier compatible devices [SOLVED]
Replies: 3
Views: 3391

Re: Zerotier compatible devices [SOLVED]

From this page: https://help.mikrotik.com/docs/display/ROS/ZeroTier MikroTik has added ZeroTier to RouterOS v7.x as a separate package for the ARM/ARM64 architecture. (only) So look at this page: https://mikrotik.com/products/matrix And you see RB3011 ARM 32bit RB2011 MIPSBE And you need to download...
by Jotne
Sun Jul 03, 2022 12:01 pm
Forum: Scripting
Topic: how to get numbers in message [SOLVED]
Replies: 5
Views: 1273

Re: how to get numbers in message [SOLVED]

Is it not in a more standard format? It would help if you post more real example. Not sure if there is a quick fix. You can loop trough one and one character in the string, test if its a number, if yes, save it and start a counter. If then 10 number are found one after one, then this is the phone nu...
by Jotne
Tue Jun 28, 2022 5:21 pm
Forum: Announcements
Topic: v7.4beta [testing] is released!
Replies: 189
Views: 62226

Re: v7.4beta [testing] is released!

Please stay on topic. Deleting offtopic now
OK, but what is the answer to my question. You do say that every new change log do show all added stuff since main release. My post clearly that what is sad, does not add up.
by Jotne
Tue Jun 28, 2022 2:21 pm
Forum: Announcements
Topic: v7.4beta [testing] is released!
Replies: 189
Views: 62226

Re: v7.4beta [testing] is released!

Nothing is added twice. BETA releases always include ALL changes since last non-BETA. This is how it's always been. The reason is that when 7.4 will be released, it will have all changes from last stable Not true at all. How do you then explain that change log for beta2 is much larger than beta4 an...
by Jotne
Sun Jun 26, 2022 11:50 pm
Forum: General
Topic: online demo routers don't work
Replies: 2
Views: 2544

Re: online demo routers don't work

Demo2 does work, but asks me to change password.

If you like to try RouterOS, just download an ISO file and install it to an PC or VmWare. Or what many other does, download EVE-NG and install RoterOS there. (all free)
Then you can test and learn it.
by Jotne
Sun Jun 26, 2022 11:45 pm
Forum: General
Topic: Long-term v7?
Replies: 5
Views: 3536

Re: Long-term v7?

Why there is not a long-term on v7? if i upgraded my router from 6.48.6 long term to 7.3.1, Is there any problem that effect user-manger and hotspot It will be ready when its ready. What you can do is to test the 7.3.1 on a equal router as you have and see if all function works as expected, then yo...
by Jotne
Sat Jun 25, 2022 9:25 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

NB. If you upgrade Splunk to 9.0, you will get some warnings. I have locked at them, and there are no big error.
It will be fixed in next version of MikroTik app for Splunk :)
by Jotne
Sat Jun 25, 2022 9:21 pm
Forum: Scripting
Topic: Advanced Netwatch
Replies: 4
Views: 2992

Re: Advanced Netwatch

You do not need two script. Use same script for both up/down and then use the status variable to see if its up/down as I already posted above: https://forum.mikrotik.com/viewtopic.php?p=888800#p888800 Any reason for using global variable in the script? Use local variable if you do not intend to stor...
by Jotne
Sat Jun 25, 2022 9:19 pm
Forum: Scripting
Topic: How to GET current netwatch host inside down-script [SOLVED]
Replies: 2
Views: 1246

Re: How to GET current netwatch host inside down-script [SOLVED]

See example where host and other variable are used to use same script for up/down logging here:
viewtopic.php?p=888800#p888800
by Jotne
Sat Jun 25, 2022 10:44 am
Forum: Scripting
Topic: time in where clause
Replies: 5
Views: 973

Re: time in where clause

The logging format problem hs been an issue for many many years and Mirkotik are not willing to fix it. Look at this thread form 2014, nothing has change for 7 years?????? https://forum.mikrotik.com/viewtopic.php?t=85015 MT do recommend store the logs on to an syslog server. I now this worsk, since ...
by Jotne
Fri Jun 24, 2022 9:21 am
Forum: Scripting
Topic: time in where clause
Replies: 5
Views: 973

Re: time in where clause

A quick search:
viewtopic.php?t=77628
by Jotne
Wed Jun 22, 2022 10:03 pm
Forum: Scripting
Topic: Help for block user use netshare
Replies: 20
Views: 4373

Re: Help for block user use netshare

Perhaps you did not know what I mean when a user uses the Internet via a username and password by the netshareapp program on his phone that redistributes the Internet. I can do the same with any router. Use wifi and connect it to your network. Add one or more PC on the inside of the router. Use pc ...
by Jotne
Wed Jun 22, 2022 5:35 pm
Forum: Scripting
Topic: Help for block user use netshare
Replies: 20
Views: 4373

Re: Help for block user use netshare

How can you prevent that I do use my user name and password on a router (mikrotik) that is setup with NAT. You will then se only one mac and there can many user behind that mac.
by Jotne
Wed Jun 22, 2022 2:01 pm
Forum: Scripting
Topic: Advanced Netwatch
Replies: 4
Views: 2992

Re: Advanced Netwatch

I do use same script for both up and down in netwatch.
viewtopic.php?p=888800#p888800

You can just change :log to telegram
by Jotne
Mon Jun 20, 2022 2:01 pm
Forum: General
Topic: Upgrade RouterOS 5.21 and 5.26 to 6.32.4? [SOLVED]
Replies: 10
Views: 1570

Re: Upgrade RouterOS 5.21 and 5.26 to 6.32.4? [SOLVED]

True.

But if you use Winbox from internet, hacker can do as well. (due to bug)
So use VPN if you need remote admin.
by Jotne
Mon Jun 20, 2022 1:01 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

I do agree that it may be wrong. Updated to this:
caps,(?:info|debug).*?: (?<ap>[^:]+): selected channel (?<frequency>\d+)\/(?<widt>\d+)?-?(?<extensionChannel>\w+)\/(?<standard>[^\/]+)\/\S+\((?<dBm>\d+)dBm
by Jotne
Mon Jun 20, 2022 12:23 pm
Forum: RouterOS beta
Topic: Health readings with v7 [SOLVED]
Replies: 50
Views: 25826

Re: Health readings with v7 [SOLVED]

You should never use internal ID in script. They changes all the time.

Some like this should do.
:local health [/system health get [find name="psu2-voltage"]]
by Jotne
Mon Jun 20, 2022 11:53 am
Forum: General
Topic: Upgrade RouterOS 5.21 and 5.26 to 6.32.4? [SOLVED]
Replies: 10
Views: 1570

Re: Upgrade RouterOS 5.21 and 5.26 to 6.32.4? [SOLVED]

You are correct. Found this.
What's new in 6.34 (2016-Jan-29 10:25):

*) mipsle - architecture support dropped (last fully supported version 6.32.x);
Its time to upgrade some hardware.
by Jotne
Sun Jun 19, 2022 8:42 pm
Forum: General
Topic: Upgrade RouterOS 5.21 and 5.26 to 6.32.4? [SOLVED]
Replies: 10
Views: 1570

Re: Upgrade RouterOS 5.21 and 5.26 to 6.32.4? [SOLVED]

You should upgrade to latest long term release. Older version has a flaw that make hacker can take control of your router.
by Jotne
Thu Jun 16, 2022 3:50 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Do you say that the reges is not correct? When I test regex: caps,(?:info|debug).*?: (?<ap>[^:]+): selected channel (?<frequency>\d+)\/(?<widt>\d+)?-?(?<extensionChannel>\w+)\/(?<standard>[^\(]+)\((?<dBm>\d+)dBm On this data caps,info MikroTik: AP 2 - 5GHz: selected channel 5680/20-eeCe/ac/DP(27dBm)...
by Jotne
Fri Jun 10, 2022 10:38 am
Forum: General
Topic: ASK [bug]
Replies: 1
Views: 356

Re: ASK [bug]

What is ASK? as in "I ask you some"
Maybe edit the thread with some better subject.
by Jotne
Thu Jun 09, 2022 7:08 am
Forum: Scripting
Topic: ROS 6.49.6 Script log messages not showing
Replies: 16
Views: 1882

Re: ROS 6.49.6 Script log messages not showing

Test it on another router with default config. If you do not have another router to test on, download and install EVE NG and make a virtual router there. It 100% free.
by Jotne
Wed Jun 08, 2022 8:40 pm
Forum: Scripting
Topic: ROS 6.49.6 Script log messages not showing
Replies: 16
Views: 1882

Re: ROS 6.49.6 Script log messages not showing

As I posted above:
 /system logging export verbose
by Jotne
Wed Jun 08, 2022 1:35 pm
Forum: Scripting
Topic: ROS 6.49.6 Script log messages not showing
Replies: 16
Views: 1882

Re: ROS 6.49.6 Script log messages not showing

Problem is that OP does not see anything in the log :) Buts a smart log ide rextended: :log info $cnt; :set cnt ($cnt + 1) But if this hits loop and hops, it will not match line number so can be some hard to track back to where it stopped. I tried to replace the :log info to :put and put all the scr...
by Jotne
Wed Jun 08, 2022 1:32 pm
Forum: Scripting
Topic: how to dynamic block unwanted ips?
Replies: 7
Views: 2231

Re: how to dynamic block unwanted ips?

This may just be port tester. You can block IP trying to get inn if there are x number of failed attempts. (Solution found in this forum) I do use it. You can block all IP trying to use a port that is not open on your router, for example for 24 hours. This stops port scanners as soon as it hits firs...
by Jotne
Wed Jun 08, 2022 1:20 pm
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5331

Re: v7.3 [stable] is released!

The problem is that it does not work at all in scenarios where the stored password is leaked. E.g. someone puts it in their RouterOS config and posts a /export show-sensitive somewhere by mistake, or there is some bug in some device (can be anything, not just a MikroTik router) that allows reading ...
by Jotne
Wed Jun 08, 2022 8:40 am
Forum: Scripting
Topic: ROS 6.49.6 Script log messages not showing
Replies: 16
Views: 1882

Re: ROS 6.49.6 Script log messages not showing

Then you have changed some log settings. I do get logs while running the script on 6.49.1 05:38:20 script,info Test if DNS exist, if not, the script stop with error 05:38:20 script,info Test passed 05:38:26 script,info DynuDDNS: dont need changes 05:38:41 script,info Test if DNS exist, if not, the s...
by Jotne
Wed Jun 08, 2022 8:33 am
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5331

Re: v7.3 [stable] is released!

Ask MT, they encourage the version should match as best practice. Either way, does it make sense to have firmware version 3.1 but ROS 7.3? It very very rarely contains fixes for already released products and that is why we do not believe that it is worth forcing this upgrade and making a ROS upgrad...
by Jotne
Wed Jun 08, 2022 12:26 am
Forum: Scripting
Topic: ROS 6.49.6 Script log messages not showing
Replies: 16
Views: 1882

Re: ROS 6.49.6 Script log messages not showing

Add all your lines between { } and change all :log info to :put The cut and past script to terminal to se what is going on. You will then get output in the terminal window instead in the logs. Some times I do add :put "1" :put "2" etc inn between lines to see what the path the sc...
by Jotne
Wed Jun 08, 2022 12:20 am
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5331

Re: v7.3 [stable] is released!

I do agree in that, but it would be better that firmware and RouterOS was just one thing, if it was to always upgrade both.
by Jotne
Tue Jun 07, 2022 11:53 pm
Forum: General
Topic: posts not strictly related to: v7.3 and v7.3.1 [stable]
Replies: 52
Views: 5331

Re: v7.3 [stable] is released!

Firmware version should always match RouterOS version, too many “admins” run on firmware version 3.1 and ROS v7 and complain about problems. Why? Do you have a change list for all the firmware version so you know what has been updated, and you can see that its needed? PS to any auto upgrade or upgr...
by Jotne
Tue Jun 07, 2022 10:54 pm
Forum: General
Topic: No more mail with google
Replies: 11
Views: 8202

Re: No more mail with google

by Jotne
Tue Jun 07, 2022 10:14 pm
Forum: Scripting
Topic: ROS 6.49.6 Script log messages not showing
Replies: 16
Views: 1882

Re: ROS 6.49.6 Script log messages not showing

I have not tested the script, but cleaned ut up: Removed not needed ; at end of some lines. Added TAB to make it easier to read. Change global to local variable. If you do not need to store the variable for later use or use it in other script, use local Removed " at end of script. It may break ...
by Jotne
Tue Jun 07, 2022 9:52 pm
Forum: Announcements
Topic: v7.4beta [testing] is released!
Replies: 189
Views: 62226

Re: v7.4beta [testing] is released!

@Jotne: open a ticket as it's not a version-specific issue.
Have already done some years ago, and was told that they will look at it on a later release.
Posted a new support request. #[SUP-84077]
by Jotne
Tue Jun 07, 2022 8:54 pm
Forum: Announcements
Topic: v7.4beta [testing] is released!
Replies: 189
Views: 62226

Re: v7.4beta [testing] is released!

Now with the new beta, please use some time to get the logging more uniform. Prefix mess: https://forum.mikrotik.com/viewtopic.php?t=124291 Timestamp should be in ISO 8601 format, not jun/02/2022 Events that may log more than one line should have the same ID. Example IPSec login. If many users logs ...
by Jotne
Tue Jun 07, 2022 11:23 am
Forum: Scripting
Topic: Netwatch hAP Lite doesn't work automatically
Replies: 3
Views: 555

Re: Netwatch hAP Lite doesn't work automatically

I made a script for logging WireGuard using NetWatch, see here:

viewtopic.php?p=888800#p888800
by Jotne
Mon Jun 06, 2022 11:29 pm
Forum: Announcements
Topic: WinBox v3.36 released!
Replies: 38
Views: 27810

Re: WinBox v3.36 released!

Its not an issue, its an feature request.
by Jotne
Mon Jun 06, 2022 7:27 pm
Forum: General
Topic: are there events which can be used to trigger scripts other than scheduled triggers
Replies: 4
Views: 752

Re: are there events which can be used to trigger scripts other than scheduled triggers

Hi,
are there events which can be used to trigger scripts other than scheduled triggers?
Netwatch can also trigger scripts.
But in your case DHCP script are the path to take.
by Jotne
Mon Jun 06, 2022 5:59 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

All updated. But could you post a log line that this will match on? EXTRACT-mikrotik_caps-man_frequency = caps,(info|debug).*?: (?<ap>[^:]+): selected channel (?<frequency>\d+)\/(?<widt>\d+)?-?(?<extensionChannel>\w+)\/(?<standard>[^\(]+)\((?<dBm>\d+)dBm I do not have/use capsman, so any help is app...
by Jotne
Mon Jun 06, 2022 10:49 am
Forum: Beginner Basics
Topic: Yet another port forwarding noob...
Replies: 9
Views: 853

Re: Yet another port forwarding noob...

I was trying to avoid asking for a public static IP (because I thought I could work around it) but that might be the answer after all. You do not need a static IP, just a public ip, not the one see in your router 100.65.x.x that is private. If this is an larger ISP, I guess he will not help you and...
by Jotne
Sun Jun 05, 2022 11:15 pm
Forum: Beginner Basics
Topic: Access denied from WAN
Replies: 19
Views: 3037

Re: Access denied from WAN

Where do rmelin router come inn to play. Does it have 8291 port that you can access? You have confirmed that ISP does not block 8291 in their net. For test you can open port 8291, but should not be done for some in production. Use VPN. And I do hope you do not use 7.3rc1 in production as vell, Its n...
by Jotne
Sun Jun 05, 2022 8:49 pm
Forum: Beginner Basics
Topic: Access denied from WAN
Replies: 19
Views: 3037

Re: Access denied from WAN

@OP
Rmelin router is an router you test instead of Mikrotik?

Do you have an public IP on your router?
See output of:
/ip address print
To test if a port is open the easy way, you can go to:
https://canyouseeme.org/
and type in the port you are testing. Should respond with a green Success
by Jotne
Sun Jun 05, 2022 8:37 pm
Forum: Beginner Basics
Topic: Yet another port forwarding noob...
Replies: 9
Views: 853

Re: Yet another port forwarding noob...

Good catch Sob @anav I guess it 6.47 100.64.0.0/10 100.64.0.0–100.127.255.255 #IP 4194304 Private network Shared address space[5] for communications between a service provider and its subscribers when using a carrier-grade NAT. With this IP (100.65.46.11) you are behind NAT out of your control, so y...
by Jotne
Sun Jun 05, 2022 10:44 am
Forum: Beginner Basics
Topic: Access denied from WAN
Replies: 19
Views: 3037

Re: Access denied from WAN

DO NOT OPEN ADMIN INTRAFACE FROM INTERNET. EVEN FOR TEST Use VPN to administrate your device from remote location. If VPN can not be used, follow this list to make connection some more secure. 1. Use another port than default. 2. Use port knocking. This prevents someone from seeing open ports. 3. U...
by Jotne
Sat Jun 04, 2022 8:32 pm
Forum: Scripting
Topic: Facebook Mobile app and youtube block
Replies: 6
Views: 2571

Re: Facebook Mobile app and youtube block

This we do as well, but you need 100% control of all clients connected to your net to do that. That would exclude all home net.
by Jotne
Sat Jun 04, 2022 5:21 pm
Forum: Scripting
Topic: Facebook Mobile app and youtube block
Replies: 6
Views: 2571

Re: Facebook Mobile app and youtube block

Not possible.
User can just use DoH or VPN and bypass everything.
by Jotne
Thu Jun 02, 2022 11:27 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3rc [testing] is released!

If MikroTik ask me about only one feature to fix, then I answer in first place LOGGING. IPSec or wireless or vpn's have one very old problem. Please add some uniq id to each peer in IPSec, mac in wireless, id in vpn... because when I have e.g. 40x IPSec tunnel mode then understand what log line is ...
by Jotne
Tue May 31, 2022 10:54 pm
Forum: Scripting
Topic: Can a script be created if a wrong login name is used
Replies: 53
Views: 11964

Re: Can a script be created if a wrong login name is used

No its not a simple delete commands for the logs. You can set the log size to 0 and back to 1000 to clean it. But you can store log id in your script and the and every time scripts run, only examine logs form the store id to the last id in the log. Since scripting and logging are limited in RouterOS...
by Jotne
Tue May 31, 2022 10:45 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

Please MikroTik, do not rename threads and post RC in its own thread as before. This just makes a messy thread. RC was always its own thread: 7.2rc7 https://forum.mikrotik.com/viewtopic.php?t=184585 6.49rc https://forum.mikrotik.com/viewtopic.php?t=178853 6.48rc https://forum.mikrotik.com/viewtopic....
by Jotne
Tue May 31, 2022 8:49 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

It could be today or this week itself.
Or not.

Why speculate. It comes when it comes.
by Jotne
Sun May 29, 2022 7:38 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

Maybe a moderator should make a own Cake thread and move all Cake post over there.
by Jotne
Sat May 28, 2022 8:41 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

I don’t see changelog for v40 Change log for v40 is in this thread: https://forum.mikrotik.com/viewtopic.php?p=932950#p932950 But change log for .33 mention in the thread is missing. (you can see it over here: https://mikrotik.com/download/changelogs/testing-release-tree) Edit Alfer closer inspecti...
by Jotne
Fri May 27, 2022 8:39 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

What do you see that I do not see?
I see only v34, v37 and v40
by Jotne
Thu May 26, 2022 11:56 pm
Forum: Scripting
Topic: Netwatch style script
Replies: 29
Views: 12860

Re: Netwatch style script

i made a script that do log up/down message using netwatch, that can be used to monitor various thing. Eks WireGuard.
viewtopic.php?p=888800#p888800
by Jotne
Thu May 26, 2022 11:33 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Likely the problem is that a complete overhaul of the logging system would make some people (who have invested time in handling the mess as it is) angry...
One of them is me, since I have to rewrite the Splunk Mikrotik logging.
But its worth it.
by Jotne
Thu May 26, 2022 9:22 pm
Forum: General
Topic: Mikrotik - assign same wireless to two bridges
Replies: 8
Views: 890

Re: Mikrotik - assign same wireless to two bridges

You could also use one Bridge with multiple VLAN instead if multiple Bridges.
by Jotne
Thu May 26, 2022 9:14 pm
Forum: General
Topic: Is there any way to hide the RED comment?
Replies: 36
Views: 8454

Re: Is there any way to hide the RED comment?

Sure, but I agree with OP that it doesn't seem very professional with screens full of red warnings that every connection is unsafe.
Are OP logged inn to your router (winbox/web) and have the log window open all time?
I would say that Winbox/web are for configuration and searching for problems.
by Jotne
Thu May 26, 2022 9:08 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

ppp,error,critical: 217.67.*.*: Encryption got out of sync - disabling At what severity level is this message? Error or Critical From Syslog Severity level https://en.wikipedia.org/wiki/Syslog 0 Emergency 1 Alert 2 Critical 3 Error 4 Warning 5 Notice 6 Informational 7 Debug Please Mikrotik fix the ...
by Jotne
Tue May 24, 2022 7:57 am
Forum: General
Topic: Are there any limitation in number of interface lists ?
Replies: 9
Views: 742

Re: Are there any limitation in number of interface lists ?

Is this some you have in production, or some you like to setup? Can you post the config?
by Jotne
Tue May 24, 2022 12:14 am
Forum: General
Topic: Are there any limitation in number of interface lists ?
Replies: 9
Views: 742

Re: Are there any limitation in number of interface lists ?

PS no need to make two post about the same. You can do many quote in one post.

Still does not understand what is your goal is. Is the some in production, or just for test?
Make a design drawing.
by Jotne
Mon May 23, 2022 9:56 pm
Forum: General
Topic: Are there any limitation in number of interface lists ?
Replies: 9
Views: 742

Re: Are there any limitation in number of interface lists ?

How many interfaces do you have since you need more than 200 interface lists?
by Jotne
Mon May 23, 2022 2:30 pm
Forum: General
Topic: Feature Request: Disable log from logging by the specified service
Replies: 7
Views: 1700

Re: Feature Request: Disable log from logging by the specified service

You must still be misreading the issue, as issues presented here is not about your personal problems and solutions, rather errors and flaws in the RouterOS implementation. 1. OP han not replayed back saying anything about what is wrong and what is correct. 2. From the title " Feature Request &...
by Jotne
Mon May 23, 2022 10:45 am
Forum: General
Topic: Feature Request: Disable log from logging by the specified service
Replies: 7
Views: 1700

Re: Feature Request: Disable log from logging by the specified service

When API logs inn, there will be written some to the logs. Internal logs has a limit, so it will be filled up by repeating stuff. Example on my router. log.png This does not give any problem for me, since I do send all logs to an external syslog/splunk server. There I can filter out what I do like t...
by Jotne
Mon May 23, 2022 8:06 am
Forum: Scripting
Topic: flushing firewall connections on a specific interface?
Replies: 2
Views: 825

Re: flushing firewall connections on a specific interface?

Have you tried:
/ip firewall connection remove [find where dst-address~"your_public_ip_on_interface_xxx"]
Here you can specify what outside IP you like the connection be cleared for.
by Jotne
Sun May 22, 2022 8:23 am
Forum: Scripting
Topic: Automate Script [SOLVED]
Replies: 12
Views: 2130

Re: Automate Script [SOLVED]

This scripts will write a file every minute to the flash drive. Would that shorten the flash life? I would suggest you do monitor the router using an external program like splunk. Here you can see many routers uptime and when they restarted. This is my garage router. You can see uptime for 17 days a...
by Jotne
Sun May 22, 2022 7:57 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

I am getting the voltage this way. /system health :put [get [find where name=voltage] value] Its more inline with the rest of my scripting. After som testing, it seems that value-name are not needed if you specify what you need after the data id. Differences: This works :put [get [find where name=vo...
by Jotne
Sun May 22, 2022 7:50 am
Forum: Announcements
Topic: v6.49.6 [stable] is released!
Replies: 56
Views: 85957

Re: v6.49.6 [stable] is released!

And in English that would be? Using google translate hello friends of the group, has it happened to someone that they have updated a RouterBOARD 750G r3 to version 6.49.6 and it stops saving configurations, that is, when it is turned off or restarted, it returns the last changes after the update. so...
by Jotne
Fri May 20, 2022 11:40 am
Forum: General
Topic: Feature Request: Disable log from logging by the specified service
Replies: 7
Views: 1700

Re: Feature Request: Disable log from logging by the specified service

You can use an external log server. There you can easily filter out what you do not want.
by Jotne
Wed May 18, 2022 1:26 pm
Forum: General
Topic: Renaming files (request)
Replies: 1
Views: 748

Renaming files (request)

I was looking for ways to rename files on RouterOS. Why? I like to modify my backup script, so that it only sends backup/export files if file size are change. Testing for size is simple, so after backup is send, I will rename export to old_export file. Next run test size and if different send new ex...
by Jotne
Wed May 18, 2022 11:54 am
Forum: Scripting
Topic: renaming backups
Replies: 9
Views: 2591

Re: renaming backups

Are you doing that on the router it self?
by Jotne
Wed May 18, 2022 11:28 am
Forum: Scripting
Topic: renaming backups
Replies: 9
Views: 2591

Re: renaming backups

This way is better, more readable :)

I was looking for how to compare two files if possible, and only take new backup and send it if different from previous backup.
checksum if possible or size.
by Jotne
Wed May 18, 2022 10:20 am
Forum: Beginner Basics
Topic: converting .backup to plain text
Replies: 19
Views: 17327

Re: converting .backup to plain text

This is why I always backup all my routers with both backup file and export config. But its interesting that there are programs to unpack the backup file, never seen that before. By converting the backup file, the OP my see why he can not reach or how to reach the router after backup file is restored.
by Jotne
Wed May 18, 2022 9:17 am
Forum: Scripting
Topic: renaming backups
Replies: 9
Views: 2591

Re: renaming backups

I do reply to this old post, since it may help other. Problem is that file name can not contain / So to get it to work, this character has to be removed or replaced to some like this { :local id [/system identity get name] :local time [/system clock get time] :local date [/system clock get date] :lo...
by Jotne
Wed May 18, 2022 8:51 am
Forum: Beginner Basics
Topic: Port Forwarding issue
Replies: 7
Views: 868

Re: Port Forwarding issue

Remove the router, setup a linux pc where you change ssh port from 22 to 1212. Connect it to your IPS and test it you can reach that from internet.
If yes, some is wrong with RouterOS config, if no, ISP problems.
by Jotne
Mon May 16, 2022 9:39 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Then splunk does not see the file.
/opt/splunk/etc/system/local/inputs.conf
It can be a permission settings, if its there.
If I do run Splunk a non-root user, f.eks as a splunk user, I make sure all files under /opt/splunk has same rights.
by Jotne
Mon May 16, 2022 8:54 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

In folder (in linux)
/opt/splunk/bin
run
./splunk btool inputs list | grep udp
You should see:
[monitor:///data/syslog/udp/.../*.log]
[udp]
by Jotne
Mon May 16, 2022 8:17 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Then you have skipped this part in rsyslog setup: To make Splunk read rsyslog data make this file: %SplunkHome%/etc/system/local/inputs.conf [monitor:///data/syslog/udp/.../*.log] sourcetype = rsyslog host_segment=4 [monitor:///data/syslog/tcp/.../*.log] sourcetype = rsyslog host_segment=4 NB Splunk...
by Jotne
Mon May 16, 2022 7:22 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

It seems that rsyslog data looks fine. But to get the firewall data in firewall dashboard correctly, you should name the rule as in section. 2c In splunk go to this setting: Settings->Data Input->Files & Directories Do you see a line starting with? /data/syslog/udp/.../*.log This command index=*...
by Jotne
Mon May 16, 2022 5:31 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Whats inn those files? paste some lines. See section 3b Debuging

If syslog folder has data, it could be one of two.
Not using MikroTik tag (Capital M and capital T)
Splunk not reading data.

What do search for
index=*
give
by Jotne
Mon May 16, 2022 1:16 pm
Forum: Beginner Basics
Topic: Port Forwarding issue
Replies: 7
Views: 868

Re: Port Forwarding issue

Not an answer to your question, but [*] never open opp 8192 from internet to admin your router. You asking for problems. add action=accept chain=input dst-port=8291 protocol=tcp See this post: https://forum.mikrotik.com/viewtopic.php?p=870631#p870631 set winbox address=192.168.1.0/24 This helps some...
by Jotne
Mon May 16, 2022 9:56 am
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

100 email to support@mikrotik.com would be better.
by Jotne
Mon May 16, 2022 8:28 am
Forum: Scripting
Topic: MikroTik PCC and ECMP Load Balancing script Generator over Unequal multi WAN Links [SOLVED]
Replies: 17
Views: 6474

Re: MikroTik PCC and ECMP Load Balancing script Generator over Unequal multi WAN Links [SOLVED]

You should never open Winbox directly from outside, your router will be hacked...
.
winbox.png
See this link:
viewtopic.php?p=870631#p870631
by Jotne
Mon May 16, 2022 8:22 am
Forum: General
Topic: Bandwidth usage per IP
Replies: 28
Views: 17570

Re: Bandwidth usage per IP

5. How to read report?
can you do? http://your.router.ip/xxxx
by Jotne
Sun May 15, 2022 11:08 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Updated section 1f, to make clear your can not use UDP/514 in Splunk if Splunk is not run as root. You then need external rsyslog server.
by Jotne
Sun May 15, 2022 7:03 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Ahh, If you use rsyslog, it uses UDP port 514, so you can not add it to Splunk. Only one app can use one given port. And since you need to be root to use port 514 (<1024), the app needs to run as root. And since its not recommended to run Splunk as root, I let rsyslog get the data by it listen to po...
by Jotne
Sun May 15, 2022 2:27 pm
Forum: General
Topic: USB over IP
Replies: 11
Views: 4133

Re: USB over IP

Do you mean that you should connect an USB mouse and when you use the Mouse, it should move the cursor on a remote machine.
This is possible, but not with Mikrotik.
There are hardware that can do that or software that can be used to emulate USB.
by Jotne
Sun May 15, 2022 2:18 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Did try to send you an email, but did not get delivered, so did try one more just now. I do use Ubuntu and there all rsyslog are installed as default in folder /etc/rsyslog.d/ and as user root. In the config there are settings that points to where to store syslog data, udp.conf that points to folder...
by Jotne
Sat May 14, 2022 9:59 pm
Forum: Beginner Basics
Topic: How to remove a dynamic DNS?
Replies: 17
Views: 7255

Re: How to remove a dynamic DNS?

add action=accept chain=input comment="Remote access to Mikrotik Igor" dst-port=8291 protocol=tcp See my reply here: https://forum.mikrotik.com/viewtopic.php?p=870631#p870631 /ip firewall filter add action=accept chain=input comment="Remote access to Mikrotik Igor" dst-port=8291...
by Jotne
Sat May 14, 2022 8:19 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

7.3beta40 is available, why is it buried in this thread.
This is how beta are posted. Look at older beta threads and you will find all beta version in just one thread for each main version.
by Jotne
Fri May 13, 2022 7:59 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

Remember this is just one beta version. MT do read this forum and they see user reaction to what they do. So no need 100 post about the same.
by Jotne
Fri May 13, 2022 2:31 pm
Forum: Beginner Basics
Topic: How to remove a dynamic DNS?
Replies: 17
Views: 7255

Re: How to remove a dynamic DNS?

Just remove check mark from "Use Peer DNS" in DHCP client config on RouterOS like here:
.
dns.png
by Jotne
Fri May 13, 2022 1:40 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Splunk can do all you ask about and more. Nearly unlimited possibility. It do cost allot of money if you put it inn to a large scale company, but may be the best and most flexible solution out there. For your IP address list, you can hav tem in a csv file that Splunk uses. This fil can be updated au...
by Jotne
Fri May 13, 2022 10:55 am
Forum: Scripting
Topic: Get "Bridge port" from address "/ip/arp" via API
Replies: 3
Views: 1684

Re: Get "Bridge port" from address "/ip/arp" via API

Its clearly a bug. On 7.x I do see the bridge port in Winbox but not at
/ip arp print detail
nor
:put [/ip arp get *1]
Send an email to support@mikrotik.com and report it as bug.
by Jotne
Fri May 13, 2022 8:18 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

1. Can a report be generated for the individual device? Yes 2. Can the script log the address list so I can perform an audit on affected IPs. Yes 3. I dont understand your naming convention...are you referring to the comment given to the rules? Yes its the naming of filter/nat rules to make it easi...
by Jotne
Thu May 12, 2022 10:21 am
Forum: General
Topic: Download traffic is not showing on Interface!
Replies: 21
Views: 2171

Re: Download traffic is not showing on Interface!

Can you not setup a Router in VM with at least 2 interface. It will then be simpler to separate download/upload and simpler to make queues to limit the bandwidth etc.
by Jotne
Thu May 12, 2022 8:28 am
Forum: Scripting
Topic: Change all users in PPPOE profile A to profile B. [SOLVED]
Replies: 4
Views: 2185

Re: Change all users in PPPOE profile A to profile B. [SOLVED]

Here you go:
{
/ppp secret
:foreach id in=[find where profile="Profile-A"] do={
	set $id profile="Profile-B"
}
}
by Jotne
Wed May 11, 2022 11:29 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Here is output of my settings /ip/kid-control> export # may/11/2022 22:25:17 by RouterOS 7.2.3 # software id = E4B6-AAAA # # model = RouterBOARD 750G r3 # serial number = xxxxx /ip kid-control add fri=0s-1d mon=0s-1d name=Monitor sat=0s-1d sun=0s-1d thu=0s-1d tue=0s-1d wed=0s-1d To see the actual da...
by Jotne
Wed May 11, 2022 8:05 am
Forum: Beginner Basics
Topic: Can ping IP's/Websites, but no internet. [SOLVED]
Replies: 61
Views: 14112

Re: Can ping IP's/Websites, but no internet. [SOLVED]

I am really AGAINST DoH in General and DoT instead would please me. DoH should only be used in countries where the people are oppressed and can't have free gathering of information in an other way. After https was introduced, DNS was the most easy way for ISP to log what you do. I am living in a fr...
by Jotne
Tue May 10, 2022 7:05 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

I would have no problem to make this app better and working together :) Yes its the same app that has been around since at least 2017. My level of programming skill is not at a high level, but know some and also working with splunk as a main work. We have 50+ Splunk server and 1+ TB a day from 3k+ s...
by Jotne
Tue May 10, 2022 2:22 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Small bug found that will come in 3.7 if you do use rsyslog. Quick fix to get it to work. Change this part of props.conf from [rsyslog] TRUNCATE = 10000 TRANSFORMS-dns = remove_dns_query,remove_dns_answer TRANSFORMS-force_mikrotik = force_mikrotik_st,force_mikrotik_ix To [rsyslog] TRUNCATE = 10000 T...
by Jotne
Tue May 10, 2022 11:56 am
Forum: General
Topic: Unknown IP address on ether1
Replies: 39
Views: 3965

Re: Unknown IP address on ether1

If you can post the config of the router, it would help some to investigate.
by Jotne
Mon May 09, 2022 12:28 pm
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 18809

Re: Backup config to Gmail v1.4 [SOLVED]

When something needs to be run on both versions, don't use syntax compatible only with v7 ;)

:local Version [/system/resource get version]
->
:local Version [resource get version]

Good catch, updated.
by Jotne
Mon May 09, 2022 10:35 am
Forum: Scripting
Topic: Backup config to Gmail v1.7 [SOLVED]
Replies: 72
Views: 18809

Re: Backup config to Gmail v1.4 [SOLVED]

Script updated to v1.4 Now also sends router version information in the subject. Faster to see when router was upgraded. # # Created Jotne 2022 v1.4 # # 1.4 Added Router OS version # 1.3r Revised by REX # 1.3 / 1.2 try to fix v6/v7 compability # 1.1 added "show-sensitive" # 1.0 initial rel...
by Jotne
Mon May 09, 2022 8:11 am
Forum: Beginner Basics
Topic: NTP protocol Is Blocked by ISP [SOLVED]
Replies: 47
Views: 10060

Re: NTP protocol Is Blocked by ISP [SOLVED]

It is confirmed that the ISP is blocking NTP protocol and they will not do anything to solve it. I have to do it from my side.
Did you ask your ISP if they have an NTP server you can use?
by Jotne
Sun May 08, 2022 10:42 am
Forum: Beginner Basics
Topic: Can ping IP's/Websites, but no internet. [SOLVED]
Replies: 61
Views: 14112

Re: Can ping IP's/Websites, but no internet. [SOLVED]

Is that the full config ?
Can not be. Missing DHCP/Bridge/interface config +++
by Jotne
Sat May 07, 2022 11:52 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Splunk to analyze MikroTik Routers :)
viewtopic.php?t=179960

Signature does not show up in all post. Not sure why.
by Jotne
Sat May 07, 2022 6:43 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

File is find in section 1g) in the first post. And I did forget to upload 3.6 when I had written that it was upgraded. Fixed now.
by Jotne
Sat May 07, 2022 6:39 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Upgraded the router with memory leak in 7.1.5 as shown here: viewtopic.php?p=922854#p922854
After one day running 7.2.3 it seems to not have memory problem with same config (just upgrade).
by Jotne
Sat May 07, 2022 11:04 am
Forum: Beginner Basics
Topic: Remote access [SOLVED]
Replies: 7
Views: 3968

Re: Remote access [SOLVED]

Use google ans search for mikrotik vpn.
MikroTik do support a big variety of VPN so select the type that fits your need. (Stay away for PPTP VPN)
by Jotne
Sat May 07, 2022 9:03 am
Forum: Scripting
Topic: Connecting to Mikrotik router remotely from application running on the server through API
Replies: 1
Views: 1727

Re: Connecting to Mikrotik router remotely from application running on the server through API

Take care when setting up remote access to the router over internet. VPN is the best option. Se my post here:

viewtopic.php?t=177280
by Jotne
Fri May 06, 2022 1:39 pm
Forum: General
Topic: Is there any way to hide the RED comment?
Replies: 36
Views: 8454

Re: Is there any way to hide the RED comment?

My car GSP gives a red warning sign with the speed limit when I drive passed the speed limit. I have then some option. 1. Drive slower 2. Ignore warning 3. Turn of GPS 4. Request the producer to remove the warming. 5. Use another GPS without warning 6. ? Same for OP. He gets several post here on wha...
by Jotne
Fri May 06, 2022 1:22 pm
Forum: General
Topic: Is there any way to hide the RED comment?
Replies: 36
Views: 8454

Re: Is there any way to hide the RED comment?

If you can live with the non secure PPTP, you should have no problem with a RED comment in Winbox.

You can use an external tool to look at the VPN connection like my Splunk for MikroTik.
Dere you can setup what you like to see or not to see.
by Jotne
Fri May 06, 2022 12:20 pm
Forum: General
Topic: Is there any way to hide the RED comment?
Replies: 36
Views: 8454

Re: Is there any way to hide the RED comment?

The OP wrote the above line in his first message. Since then, almost everyone is trying to convince him to use anything else than PPTP. Am I missing anything? You miss comment like this: Ship each site a pre-configured hEX or similar to terminate a proper VPN tunnel. For instance, a site-to-site Wi...
by Jotne
Fri May 06, 2022 9:56 am
Forum: General
Topic: traffic monitoring
Replies: 9
Views: 5941

Re: traffic monitoring

by Jotne
Fri May 06, 2022 9:53 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

From what version?
by Jotne
Fri May 06, 2022 8:26 am
Forum: General
Topic: SNMP Walk works, but Get does not
Replies: 3
Views: 1294

Re: SNMP Walk works, but Get does not

Can you post the output of with oid of the line giving correct result?
by Jotne
Thu May 05, 2022 6:39 pm
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] and v7.2.3 [stable] are released!

Version 7.1.6 would be the next in long-term branch... But this is off topic, we should stop here. Off topic, but I was very surprised when I did see that 7.1.5 thread was closed in favor for 7.2.1. So is 7.2.1 same as 7.1.6? Normal MT keeps a version over a longer periode. When its stable for some...
by Jotne
Thu May 05, 2022 2:58 pm
Forum: General
Topic: Is there any way to hide the RED comment?
Replies: 36
Views: 8454

Re: Is there any way to hide the RED comment?

Time to start upgrading older hardware.
by Jotne
Thu May 05, 2022 11:44 am
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.6 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Upgraded to 3.6 # 3.6 (05.05.2022) # NB Delete old app (copy custom made config) before install v3.6 # Change data to store in Mikrotik index, instead of default index # Change how rsyslog handles data. Did fail if there was more than one type of input # Updeted script in "MikroTik DHCP to Sta...
by Jotne
Thu May 05, 2022 8:05 am
Forum: Scripting
Topic: File transfer via SFTP fails
Replies: 12
Views: 4073

Re: File transfer via SFTP fails

Cleaned up the script some. Removed ; from half of the script. Not needed at end of line. Only when multiple commands are on same line. Open up the do= commands to better see the loops. Added tabs to better see the loops. :log info "Automated Backup Started" :delay 2s :log info "Creat...
by Jotne
Wed May 04, 2022 10:03 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

Hi Jotne,I'm new to the forum and to splunk, I have my lab upstairs with an ubuntu server with rsyslog and a mikrotik rb3011/6.42.9v router, the logs arrive in my rsyslog, but I can't see them in splunk. I would appreciate any help. Do this search give any Mikrotik data? index=* You have followed t...
by Jotne
Wed May 04, 2022 9:56 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

@siscom try some search like this.
index=* sourcetype=mikrotik  eventtype IN (*tp_connection_from,*tp_user_logged_in,ppp_authentication_failed,l2tp_user_logged_out)
or
index=* sourcetype=mikrotik  ppp
Without seeing what you get its not easy,
by Jotne
Tue May 03, 2022 10:08 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] is released!

You also need WifiWave 2 packets for it briks.
by Jotne
Tue May 03, 2022 10:02 am
Forum: Scripting
Topic: How to get the received ping of ros v7.x?
Replies: 1
Views: 555

Re: How to get the received ping of ros v7.x?

Missing ping number seems to only bee seen with count=2. Try count=3 This looks like a bug and MT should fix it. [jotne@RB951-2] > :put [:ping 8.8.8.8 count=2] Columns: SEQ, HOST, SIZE, TTL, TIME SEQ HOST SIZE TTL TIME 0 8.8.8.8 56 53 17ms540us 1 8.8.8.8 56 53 17ms770us [jotne@RB951-2] > :put [:ping...
by Jotne
Tue May 03, 2022 9:58 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] is released!

Its very sily to say that I have to read forum before upgrade to stable version...when is new firmware distributed by official upgrade from HAP AC3, the firmware must be checked for this device. How anyone could explain how Mikrotik is testing new stable version when it bricks all HAP AC3????? Its ...
by Jotne
Tue May 03, 2022 8:21 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] is released!

Put it in the signature part of your user account ;)
Does not help if owner of Mikrotik Routers does not bother to read the forum.
by Jotne
Tue May 03, 2022 8:20 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] is released!

Argh the wiviwave2 package make my hAPAC3 bootloop forever...
Did you read this forum before upgrade?
Did you read the post above before you posted this post.
This is just repeating what is already known.
by Jotne
Tue May 03, 2022 8:19 am
Forum: Announcements
Topic: v7.2.2 [stable] and v7.2.3 [stable] are released!
Replies: 401
Views: 83112

Re: v7.2.2 [stable] is released!

I am really angry, as it took me literally 5-6 hours to setup and test...even with linux and dump switch in between did not work with netinstall I do not see why all is upset. Yes, its not good that software do breaks the router. Many users posts and ask for auto upgrade of routers, and this is why...
by Jotne
Tue May 03, 2022 12:04 am
Forum: Scripting
Topic: Find External IP ? [SOLVED]
Replies: 26
Views: 90242

Re: Find External IP ? [SOLVED]

all other disadvantages...
Can you give some example on that.
I know that if you posting config, you should not post serial, since it can be used to find your IP. Not a very big problem if you have secured your router well.
by Jotne
Mon May 02, 2022 6:02 pm
Forum: Scripting
Topic: Find External IP ? [SOLVED]
Replies: 26
Views: 90242

Re: Find External IP ? [SOLVED]

As I write above.
:put [/ip cloud get public-address]
by Jotne
Sun May 01, 2022 10:52 pm
Forum: Scripting
Topic: Convert uptime to date and time [SOLVED]
Replies: 46
Views: 9525

Re: Convert uptime to date and time [SOLVED]

Convert this:
:put [/system/resource/get uptime]
5w4d12:38:02
to what?
by Jotne
Sat Apr 30, 2022 11:15 pm
Forum: General
Topic: How to secure Mikrotik with FW rules?
Replies: 35
Views: 3471

Re: How to secure Mikrotik with FW rules?

add chain=input comment="allow Winbox" in-interface=ether1-gateway port=8291 protocol=tcp DO NOT OPEN ADMIN INTRAFACE FROM INTERNET!!!!!! This is just asking for trouble. Use VPN to administrate your device from remote location. If VPN can not be used, follow this list to make connection ...
by Jotne
Tue Apr 26, 2022 5:40 pm
Forum: Scripting
Topic: Can a script be created if a wrong login name is used
Replies: 53
Views: 11964

Re: Can a script be created if a wrong login name is used

Either way should be possible. I will look at it when I am back home.
by Jotne
Mon Apr 25, 2022 11:32 pm
Forum: Scripting
Topic: Can a script be created if a wrong login name is used
Replies: 53
Views: 11964

Re: Can a script be created if a wrong login name is used

When going through bad login, its possible to compare the username against all local stored user name and if not found, then do log a message.
by Jotne
Mon Apr 25, 2022 2:02 pm
Forum: Scripting
Topic: Can a script be created if a wrong login name is used
Replies: 53
Views: 11964

Re: Can a script be created if a wrong login name is used

I am not sure if the message that are logged are different if its wrong user or wrong password.
Test and se what log you get. If log are different, it should be easy to fix the script.
I am away from my mikrotik routes, so no testing (vacation in Brazil :) )
by Jotne
Mon Apr 25, 2022 1:58 pm
Forum: Announcements
Topic: v7.2.1 [stable] is released!
Replies: 240
Views: 47610

Re: v7.2.1 [stable] is released!

That was what normis just did write.
by Jotne
Sun Apr 24, 2022 11:55 pm
Forum: Beginner Basics
Topic: Manage Mikrotik from Internet
Replies: 5
Views: 810

Re: Manage Mikrotik from Internet

Make sure you use VPN to access your router.
You should also upgrade to latest long time release 6.48.6
https://mikrotik.com/download
by Jotne
Sat Apr 23, 2022 12:44 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

I have been using GreyLog for a couple of years for Syslog management on my Tiks. Can someone help me understand when using Splunk with a Tik, what would be the advantage over GreyLog? GreyLog and Splunk are the two mayor log receiving system. One is 100% free, other is free up to 500MB log / day. ...
by Jotne
Sat Apr 23, 2022 12:40 pm
Forum: Useful user articles
Topic: 📌 Tool: Using Splunk to analyse MikroTik logs 4.0 (Graphing everything) 💾 🛠 💻 📊
Replies: 365
Views: 126971

Re: &#128204; Tool: Using Splunk to analyse MikroTik logs 3.5 (Graphing everything) &#128190; &#128736; &#128187; &#1282

What do you get when search for
index=*
Do you use rsyslog or are you running Splunk as root and listen on port 514?
See section
3b) Debugging
by Jotne
Sat Apr 23, 2022 12:38 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 64
Views: 69877

Re: Recommend way to block Ads with Mikrotik

Not necessarily.
Because DoH server can be blocked, and then fallback to standard DNS.
Since you can not see what's inside HTTPS packages, you can not know if its a web site or DoH traffic. And since any can setup a DoH or DoT server, there are no way you can block this.
by Jotne
Sat Apr 16, 2022 6:39 pm
Forum: Scripting
Topic: Scrip modify scheduler date in hour
Replies: 2
Views: 527

Re: Scrip modify scheduler date in hour

Why?
by Jotne
Wed Apr 13, 2022 7:26 pm
Forum: Announcements
Topic: v7.3rc [testing] is released!
Replies: 452
Views: 105483

Re: v7.3beta [testing] is released!

I have not looked at 7.3beta, but my guess is that change log is the difference from 7.2 or 7.2.1
by Jotne
Sat Apr 09, 2022 2:23 pm
Forum: Scripting
Topic: script working in scripting won't work in netwatch, not a permission issue
Replies: 4
Views: 932

Re: Don't know why this script not work

Why not use netwatch function?
Its created for just this type of senarios.
by Jotne
Sat Apr 09, 2022 2:20 pm
Forum: Announcements
Topic: v7.2 is released!
Replies: 359
Views: 62889

Re: v7.2 is released!

I hope that one day my network interface will work
version 6 works without problems
Not the same, but you can install VmWare and use CHR version of RouterOS.
by Jotne
Tue Apr 05, 2022 2:05 pm
Forum: Announcements
Topic: v7.2 is released!
Replies: 359
Views: 62889

Re: v7.2 is released!

Changes since last rc (rc7) Find using compare duplicate cells in Excel. No new stuff added since rc7 List of all changes and when they was introduced in 7.2 train RC `7.2.0 rc5 *) api - accept "Content-Type" with specified charset; rc5 *) arm - fixed "auto" CPU frequency setting...
by Jotne
Tue Apr 05, 2022 12:35 pm
Forum: Announcements
Topic: v7.2 is released!
Replies: 359
Views: 62889

Re: v7.2 is released!

They should have made a changelog relative to 7.2rc7 as well. That is some I do miss as well. If you look at Cisco, you have a tool where you can compare each version against each other and even select different hardware. Cisco Feature Navigator https://cfnng.cisco.com/ Not sure how much you can se...
by Jotne
Sun Apr 03, 2022 2:25 pm
Forum: Scripting
Topic: Aoutomatic Upgrade router Firmwarewith scripting
Replies: 1
Views: 802

Re: Aoutomatic Upgrade router Firmwarewith scripting

Read this post: https://forum.mikrotik.com/viewtopic.php?p=788771#p788771 Never, ever let the system auto upgrade without having a hold trigger. After new firmware comes out, wait 2-3 weeks and read all post to see if any serious bug arrive. Test new software on a local test router with same hardwar...
by Jotne
Thu Mar 31, 2022 8:44 pm
Forum: Scripting
Topic: Activate Script [SOLVED]
Replies: 5
Views: 2350

Re: Activate Script [SOLVED]

Not sure where I get it from. May have seen it some place and start using it.
by Jotne
Thu Mar 31, 2022 2:50 pm
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40758

Re: v7.1.4 and v7.1.5 is released!

Does not look god. Memory does still be eaten up. Did try to turn of DoH som 6 hour ago, still going up. So in some days it reaches 100%.
RB 750Gr3 Router OS 7.1.5
Will send file to support.
.
by Jotne
Thu Mar 31, 2022 1:27 pm
Forum: Scripting
Topic: Send Public IP to telegram
Replies: 12
Views: 5428

Re: Send Public IP to telegram

local cAdd
set cAdd [/ip/cloud/get public-address]
by Jotne
Thu Mar 31, 2022 12:03 pm
Forum: Announcements
Topic: v7.2rc6 and v7.2rc7 is released!
Replies: 100
Views: 20828

Re: v7.2rc6 and v7.2rc7 is released!

but it was a little shocking moment as the PING didn´t came back.....
You should not be shocked, since this is just a test version and should not be used in production.
by Jotne
Thu Mar 31, 2022 12:02 pm
Forum: Announcements
Topic: v7.2rc6 and v7.2rc7 is released!
Replies: 100
Views: 20828

Re: v7.2rc6 is released!

No, there have been fix releases quicker than that...
From my long list of release, there has not been a faster public release (4:25) from 6.47 and up (including beta). Have not looked at releases before 6.47. But I may have missed some...
by Jotne
Thu Mar 31, 2022 9:07 am
Forum: Scripting
Topic: Send Public IP to telegram
Replies: 12
Views: 5428

Re: Send Public IP to telegram

Turn in IP Cloud on your router and get IP using this command.
:put [/ip/cloud/get public-address]
by Jotne
Thu Mar 31, 2022 9:04 am
Forum: Scripting
Topic: script about the connection speed of the interface
Replies: 5
Views: 2798

Re: script about the connection speed of the interface

Can it be a bug? What RouterOS version do you run?
by Jotne
Thu Mar 31, 2022 9:00 am
Forum: Scripting
Topic: Ping not working in script on 7.1.5?
Replies: 1
Views: 847

Re: Ping not working in script on 7.1.5?

Use netwatch, not ping in script:
viewtopic.php?p=922780
by Jotne
Thu Mar 31, 2022 8:27 am
Forum: Scripting
Topic: Activate Script [SOLVED]
Replies: 5
Views: 2350

Re: Activate Script [SOLVED]

No need to use ping in script. What you do is to use netwatch. There you can have a script for up/down information. Script name: Netwatch #################################### # Netwatch script # # Used as both up and down script # Created Jotne 2021 v1.5 # #################################### :local...
by Jotne
Wed Mar 30, 2022 9:55 pm
Forum: Announcements
Topic: v7.2rc6 and v7.2rc7 is released!
Replies: 100
Views: 20828

Re: v7.2rc6 is released!

Do you run at not standard frequency for the CPU.
/system/routerboard/settings/print
by Jotne
Wed Mar 30, 2022 6:23 pm
Forum: Announcements
Topic: v7.2rc6 and v7.2rc7 is released!
Replies: 100
Views: 20828

Re: v7.2rc6 is released!

What is the problem that you are reporting with this specific 7.2rc6 and what does it have to do with 6.4x versions?
It was just to show that in 7.x series MT has change from posting many beta version of the software to posting many RC version.
by Jotne
Wed Mar 30, 2022 2:57 pm
Forum: Announcements
Topic: v7.2rc6 and v7.2rc7 is released!
Replies: 100
Views: 20828

Re: v7.2rc6 is released!

Is RC the new Beta? I do not see that any beta has been posted for 7.2, but multiple RC. (6 so far)
7.1 was some inn between with 6 rc and 6 beta (Posted)

6.49 - 2 rc
6.48 - 1 rc
6.47 - 1 rc
6.46 - 1 rc
6.45 - 2 rc
6.44 - 1 rc
by Jotne
Tue Mar 29, 2022 10:47 pm
Forum: General
Topic: What is the best way to prevent internal traffic from leaving? [SOLVED]
Replies: 56
Views: 7093

Re: What is the best way to prevent internal traffic from leaving? [SOLVED]

This discussion has nothing, absolutely nothing to do with DNS. I'm trying to prevent traffic to 8.8.8.8 Is not 8.8.8.8 a DNS IP. What else is 8.8.8.8 used for? I just try to figure out why you request what you do to see if there is an other approach to the problem PS you do not need to Quote the w...
by Jotne
Tue Mar 29, 2022 10:18 pm
Forum: General
Topic: What is the best way to prevent internal traffic from leaving? [SOLVED]
Replies: 56
Views: 7093

Re: What is the best way to prevent internal traffic from leaving? [SOLVED]

Because if the source IP is 192.168.0.3, Google should just drop the packet , it can't send traffic back to it.
Then you should remove 8.8.8.8 DNS settings from 192.168.0.3
by Jotne
Tue Mar 29, 2022 8:33 pm
Forum: General
Topic: What is the best way to prevent internal traffic from leaving? [SOLVED]
Replies: 56
Views: 7093

Re: What is the best way to prevent internal traffic from leaving? [SOLVED]

@kevinds
Why block 8.8.8.8 for some hosts?

I have seen that Chromecast has fixed 8.8.8.8 and fails if you try to grab traffic to udp 53 and send it to another DNS.
Also if some block my DNS that I like to use, I just change to DoH or DoT.
by Jotne
Tue Mar 29, 2022 8:37 am
Forum: General
Topic: What is the best way to prevent internal traffic from leaving? [SOLVED]
Replies: 56
Views: 7093

Re: What is the best way to prevent internal traffic from leaving? [SOLVED]

Unless I'm missing something, this will blackhole all internal traffic..
No, it will only block traffic that has destination IP in the blackhole route.
by Jotne
Tue Mar 29, 2022 8:27 am
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40758

Re: v7.1.4 and v7.1.5 is released!

As seen form this post viewtopic.php?p=921640#p921640
hEX RB750Gr3 continues to leak memory since upgrade to 7.1.5
.
Memory 7.1.5.png
by Jotne
Mon Mar 28, 2022 3:39 pm
Forum: Scripting
Topic: [ROS6.x] Generate a random number in a range.
Replies: 2
Views: 1132

Re: [ROS6.x] Generate a random number in a range.

Just a quick search on this forum and you can find multiple post.
viewtopic.php?f=9&t=56933
viewtopic.php?f=9&t=175453&p=858629
by Jotne
Mon Mar 28, 2022 3:02 pm
Forum: Beginner Basics
Topic: Recommend way to block Ads with Mikrotik
Replies: 64
Views: 69877

Re: Recommend way to block Ads with Mikrotik

It will not. This is the point of Pi-hole.

Where you get DNS to your hosted webserver (on your lan), does not mater. If its DNS or DoH as long as its the public name for your server.
DoH in your browser will however bypass both your local DNS or local DoH server settings.
by Jotne
Sat Mar 26, 2022 11:56 pm
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40758

Re: v7.1.4 and v7.1.5 is released!

I do have a memory leak after upgrading a 750Fr3 (that have a large config) from 6.49.2->6.49.5->7.1.5 friday morning. After the upgrade memory usage only goes up. I will lett it go some week and follow it closely. If it does not stop, I will try to stop DoH that I have had problem with before. . Me...
by Jotne
Fri Mar 25, 2022 9:15 pm
Forum: Scripting
Topic: Reset all counters [SOLVED]
Replies: 8
Views: 5627

Re: Reset all counters [SOLVED]

/ip firewall nat reset-counters-all
Add it to a scheduler if you like to reset it a certain time.
by Jotne
Fri Mar 25, 2022 10:01 am
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40758

Re: v7.1.4 and v7.1.5 is released!

Strange, it works now after some time.

But this is a BUG for MT to fix.

In stable channel, it shows 7.1 even if I have 7.1.5. So according to MT, I should downgrade???
by Jotne
Fri Mar 25, 2022 7:36 am
Forum: Scripting
Topic: Why API Is Too Slow
Replies: 6
Views: 1844

Re: Why API Is Too Slow

No reply to an 10 year post...

And do not quote the whole post above you. Not a good habit as well.
Use the green Post Reply button under the the post to reply some.
When there are post inn between, you can quote a post, but pick only what you reply to.
by Jotne
Fri Mar 25, 2022 7:18 am
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40758

Re: v7.1.4 and v7.1.5 is released!

Upgraded a hEX RB750gv3 to 7.1.5 everything seems to went fine except when I look at System->Package In check for Updates it only show ERROR: connection timed out when I look for new version. Same for long term, stable, testing and development. I can ping mikrotik.com from terminal, so internet conn...
by Jotne
Thu Mar 24, 2022 9:24 pm
Forum: General
Topic: Port 514 filtered shell
Replies: 7
Views: 2609

Re: Port 514 filtered shell

I do not see any joke here.

To help out, please post the config.
by Jotne
Thu Mar 24, 2022 8:03 pm
Forum: Scripting
Topic: all ppp profile [SOLVED]
Replies: 20
Views: 3896

Re: all ppp profile [SOLVED]

MT does not handle upper/lower case very good.
Missing toupper/tolower (?i) +++
by Jotne
Thu Mar 24, 2022 5:33 pm
Forum: Scripting
Topic: all ppp profile [SOLVED]
Replies: 20
Views: 3896

Re: all ppp profile [SOLVED]

Hmm

I hoped that this should work, but it does not:
name~"(?i)fibr"
Did try this as well, but does not work.
name~"(\?i)fibr"
by Jotne
Thu Mar 24, 2022 3:25 pm
Forum: General
Topic: Port 514 filtered shell
Replies: 7
Views: 2609

Re: Port 514 filtered shell

https://www.speedguide.net/port.php?port=514

514 UDP Syslog
514 TCP Remote shell

But you can use nearly all port to other stuff if you like.
by Jotne
Thu Mar 24, 2022 2:19 pm
Forum: Scripting
Topic: all ppp profile [SOLVED]
Replies: 20
Views: 3896

Re: all ppp profile [SOLVED]

You need to find what you are looking for, then get all the data for the ID that find returns. print should not be used in script. :foreach Profile in=[/ppp profile find where name~"FIBR"] do={:put [/ppp profile get $Profile]} Some more clean setup. /ppp profile :foreach Profile in=[find w...
by Jotne
Thu Mar 24, 2022 1:40 pm
Forum: Scripting
Topic: executed a script on log event
Replies: 2
Views: 2107

Re: executed a script on log event

See my posts in this thread:
viewtopic.php?t=148397

It uses the log to block VPN users that do not have correct credentials.
by Jotne
Wed Mar 23, 2022 1:54 pm
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40758

Re: v7.1.4 and v7.1.5 is released!

Nope, the device was upgraded from v6.48.x -> v7.1.3 -> v7.1.5 remotely is the key word here
This is why you should (if possible) always test on a equal local device before starting on remote device.
by Jotne
Wed Mar 23, 2022 1:38 pm
Forum: General
Topic: System -> Auto Upgrade howto?
Replies: 8
Views: 31632

Re: System -> Auto Upgrade howto?

True MKX. *) dot1x - fixed "reject-vlan-id" for MAC authentication (introduced in v6.48); *) dot1x - fixed MAC authentication fallback (introduced in v6.48); *) tile - fixed bridge performance degradation (introduced in v6.47); *) webfig - fixed "PortMapping" button (introduced i...
by Jotne
Tue Mar 22, 2022 8:47 pm
Forum: General
Topic: System -> Auto Upgrade howto?
Replies: 8
Views: 31632

Re: System -> Auto Upgrade howto?

Here you see a good example on how wrong it can go on auto upgrade:
viewtopic.php?t=184318

7.1.5 was just releases some hour after 7.1.4 that did delete the routing table when upgrade.
by Jotne
Tue Mar 22, 2022 2:22 pm
Forum: RouterOS beta
Topic: Where is UPS?
Replies: 26
Views: 14321

Re: Where is UPS?

What's new in 7.1.4 (2022-Mar-21 13:23):

*) ups - fixed UPS support;
by Jotne
Tue Mar 22, 2022 1:40 pm
Forum: Announcements
Topic: v7.1.4 and v7.1.5 is released!
Replies: 202
Views: 40758

Re: v7.1.4 is released!

When will Docker be supported again? T_T T_T T_T T_T Wrong thread. This thread is about 7.1.x updates. They will normal only contain bug fixes. I do also think 7.2Rc is locked for new stuff, so post your request to support@mikrotik.com or here: https://forum.mikrotik.com/viewtopic.php?t=45934
by Jotne
Mon Mar 21, 2022 8:04 am
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43124

Re: v7.2rc4 is released!

https://forum.mikrotik.com/viewtopic.php?t=178353#p890747 We only can do it for ARM systems, no plans for MIPS now. That is not the same as that there will never be. It may come in future. We only can do it for ARM system (since we do not have time, or missing a component, or to little memory or...)
by Jotne
Mon Mar 21, 2022 7:58 am
Forum: Scripting
Topic: Email last 24hrs logs [SOLVED]
Replies: 6
Views: 2636

Re: Email last 24hrs logs [SOLVED]

You can send all logs using syslog. See link in my signature for how to use Splunk to analyze them and graph them.
by Jotne
Sun Mar 20, 2022 4:37 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43124

Re: v7.2rc4 is released!

no plans for other architecture atm as per MT
I know its only arm yet. Can you post a link to where MT stats that there will be no ZeroTier for other platform?
by Jotne
Sat Mar 19, 2022 9:10 pm
Forum: Scripting
Topic: Scripting with MAC Address/Serial Number Variables
Replies: 4
Views: 1837

Re: Scripting with MAC Address/Serial Number Variables

ohh, this was the heavily guarded secret that all ISP uses ;)
by Jotne
Sat Mar 19, 2022 5:31 pm
Forum: General
Topic: Microsoft creates tool to scan MikroTik routers for TrickBot infections
Replies: 4
Views: 1408

Re: Microsoft creates tool to scan MikroTik routers for TrickBot infections

This is just a quick walk trough on what the Microsoft script does. It may not be 100% correct (my python knowledge are not high), but should give an idea. basecommand.py Used to run other commands? dns.py /ip dns print Test if remote dns is allowed /ip dns cache print detail Test of cahce is enable...
by Jotne
Fri Mar 18, 2022 3:24 pm
Forum: Scripting
Topic: ":put" problem in scripting [SOLVED]
Replies: 17
Views: 7400

Re: ":put" problem in scripting [SOLVED]

When you do have a script that run, lets say 00:00 every night. Where do you expect :put to show its output? Do you have a terminal session open 24/7/365 and waiting for output? This is why we do have :log that sends output to log or syslog . Data can also be sent to email, ftp, http, blink the led ...
by Jotne
Fri Mar 18, 2022 12:23 pm
Forum: Scripting
Topic: New script please
Replies: 1
Views: 545

Re: New script please

I guess if you google for it, you will find various example. BUT NEVER EVER SET THIS TO AUTO!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! You could have the script to test if a flag is set on a web server. If the flag is set to yes and the script runs and see that there is a n...
by Jotne
Thu Mar 17, 2022 8:19 am
Forum: Scripting
Topic: how can save mac address in a comment after login [SOLVED]
Replies: 15
Views: 4716

Re: how can save mac address in a comment after login [SOLVED]

Cleaned up the script. Code tags, tabs, if section and removed not needed ; :foreach i in=[/ip hotspot user find where name!=default-trial] do={ :local uptime [/ip hotspot user get number=$i uptime] #if an user have 00:00:00 uptime means it's not connected right? then... :if ($uptime=00:00:00) do={ ...
by Jotne
Wed Mar 16, 2022 10:42 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43124

Re: v7.2rc4 is released!

Or not an bug at all. It may be by design. You posted it in this thread, so it is to assume that this was related to 7.2rc4.
This may be posted to support@mikrotik.com as a future request or as a bug if it ever has worked.
by Jotne
Wed Mar 16, 2022 9:07 pm
Forum: Announcements
Topic: v7.2rc4 is released!
Replies: 143
Views: 43124

Re: v7.2rc4 is released!

It removes the GRE connection on 6.x and 7.1.3?
by Jotne
Wed Mar 16, 2022 7:18 pm
Forum: Scripting
Topic: The condition is not met, why does the script keep executing?
Replies: 7
Views: 926

Re: The condition is not met, why does the script keep executing?

It seem that your picture were added as thumbnail. Not able to see details.
by Jotne
Wed Mar 16, 2022 3:58 pm
Forum: RouterOS beta
Topic: RB5009 reboots itself each 8-10 days (7.2rc3/rc4) [SOLVED]
Replies: 19
Views: 8862

Re: RB5009 reboots itself each 8-10 days (7.2rc3/rc4) [SOLVED]

Without seeing the config and information what is tried, its hard to help with anything.

So post config. Send supportfile to support@mikrotik.com
by Jotne
Tue Mar 15, 2022 7:38 pm
Forum: General
Topic: How to stop/block NetShare -tethering apps
Replies: 2
Views: 1669

Re: How to stop/block NetShare -tethering apps

I think you cant stop this. On my Huawei P30 i can set it up as an Wifi bridge (default app on phone). This will make the phone as an wifi router with nat. There are no way that router or any equipment out the outside could see what I am doing. You can monitor all wifi net around and see if there ar...
by Jotne
Tue Mar 15, 2022 5:33 pm
Forum: General
Topic: Feature requests
Replies: 1744
Views: 644292

Re: Feature requests

What logging config did you make to see this detailed logging? No config, but use this command: /system history print detail This part of my Splunk/Mikrotik script sends the data to Syslog: # Get detailed command history RouterOS >= v7 # ---------------------------------- :if ([:tonum [:pick [/syst...
  • 1
  • 2
  • 3
  • 4
  • 5
  • 13