Community discussions

Search found 810 matches

  • 1
  • 2
  • 3
  • 4
  • 5
  • 17
by Jotne
Tue Jan 22, 2019 1:19 pm
Forum: Useful user articles
Topic: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)
Replies: 108
Views: 10570

Re: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)

Do examine time on all your devices. It must be in sync.
Do use NTP on all devices to make sure time is ok.
by Jotne
Tue Jan 22, 2019 12:21 pm
Forum: General
Topic: Mikrotik per user bandwidth volume consumption report
Replies: 10
Views: 424

Re: Mikrotik per user bandwidth volume consumption report

You must be blind, look in bottom of every post. The thing in the white window was just for you to see where to see the link.

But here it is:
viewtopic.php?f=23&t=137338

Do you see the word Splunk in color red at the bottom of the message? Link is just blow it.
by Jotne
Tue Jan 22, 2019 11:40 am
Forum: Useful user articles
Topic: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)
Replies: 108
Views: 10570

Re: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)

It may be that the props filter only look at UDP:514 and syslog. When data comming in on UDP:515 it will not see that its MikroTik data. You can fix this by edit etc/apps/MikroTik/default/props.conf and add [source::udp:515] TRANSFORMS-dns=remove_dns_query,remove_dns_answer TRANSFORMS-force_mikrotik...
by Jotne
Tue Jan 22, 2019 10:51 am
Forum: General
Topic: DNS xxx.ddns.net
Replies: 8
Views: 455

Re: DNS xxx.ddns.net

Localhost... So strange.

Not strange at all. When you register a DNS name, you can add any IP you like.
So some has registered k3yhol3.ddns.net with IP 127.0.0.1


I can register myserverhome.dyndns,com with IP 127.0.0.1 but why should I do that is an other question.
by Jotne
Tue Jan 22, 2019 8:43 am
Forum: Useful user articles
Topic: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)
Replies: 108
Views: 10570

Re: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)

2.6 released # 2.6 (22.01.2019) # Added information about fast track in "traffic monitor" # Fixed typo in Traffic view. Added fast track info # Changed to checkbox in "DNS Request" # Added better sparkline "in Device List" # Added identity to "Device List" # Updated script to get identity # Removed...
by Jotne
Mon Jan 21, 2019 10:56 pm
Forum: Scripting
Topic: DynDns Script (No Logs)
Replies: 4
Views: 157

Re: DynDns Script (No Logs)

Setup IP->Cloud on you Router. You will be give an DNS some like this: 6f331abe0a160.sn.mynetname.net Not 100% if this work, but on dyndns.com you should be able to add DNS name instead of IP. May years since I used their service. So if your dyndns.com name is: myhost.dyndns.com and your IP is 195.3...
by Jotne
Mon Jan 21, 2019 7:57 pm
Forum: Beginner Basics
Topic: how to allow / block access to my network by geographical area (countries) [SOLVED]
Replies: 6
Views: 176

Re: how to allow / block access to my network by geographical area (countries) [SOLVED]

This will only block users that tries to reach the site normally. If a user likes to change source IP, he can use VPN/RDP server ++++ Example download and install Hola Better internet for you Chrome free. You can then set what country you like to be in while surfing. Remember that since this is a fr...
by Jotne
Mon Jan 21, 2019 7:50 pm
Forum: General
Topic: Help on Port Scanners
Replies: 3
Views: 154

Re: Help on Port Scanners

I have the following rules on my router: #near the top #5 add action=drop chain=input comment="Drop user that has tried blocked ports" in-interface=ether1-Wan log-prefix=\ FW_Drop_all_from_WAN src-address-list=FW_Block_user_try_unkown_port . . . . # at the bottom of the filter list #15 add action=ad...
by Jotne
Mon Jan 21, 2019 7:34 pm
Forum: Useful user articles
Topic: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)
Replies: 108
Views: 10570

Re: Using Splunk to analyse MikroTik logs 2.5 (Graphing everything)

It looks like your router tries to resolve DNS on it self and get blocked.
From router console try this.
:put [/resolve mikrotik.com]
You should get an IP as result, like 159.148.147.196
by Jotne
Mon Jan 21, 2019 6:38 pm
Forum: Useful user articles
Topic: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)
Replies: 108
Views: 10570

Re: Using Splunk to analyse MikroTik logs 2.5 (Graphing everything)

You should not see local address in the outside inn block rule. Can you post an example like this: 2019-01-21 17:25:25 FW_Drop_all_from_WAN input ether1-Wan (unknown 0) 00:05:00:01:00:01 TCP 104.131.145.9 45167 92.31.200.211 2082 San Francisco United States And yes, you can get rid of the message in...
by Jotne
Mon Jan 21, 2019 1:12 pm
Forum: General
Topic: Mikrotik per user bandwidth volume consumption report
Replies: 10
Views: 424

Re: Mikrotik per user bandwidth volume consumption report

This is my signature, click the MikroTik->Splunk:
Use Splunk to monitor your MikroTik Router

MikroTik->Splunk
by Jotne
Mon Jan 21, 2019 8:46 am
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 480

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

However, I usually name the SSIDs differently, like Corporate and CorporateSlow. You can guess which one 2.4GHz! I do that as well. It will then be up to the users if they like the one or the other. If you never connect to 2.4GHz SSID, it will always take the 5GHz SSID if you have connected to it o...
by Jotne
Sun Jan 20, 2019 10:12 pm
Forum: General
Topic: Mikrotik per user bandwidth volume consumption report
Replies: 10
Views: 424

Re: Mikrotik per user bandwidth volume consumption report

All is in the link in my signature.
by Jotne
Sun Jan 20, 2019 12:56 pm
Forum: Wireless Networking
Topic: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2
Replies: 13
Views: 480

Re: android devices chooses 2.4Ghz over 5Ghz on hAP ac^2

There are apps for android that, when installed on mobile, push device to 5GHz band even if signal strength is lower than on 2.4GHz. One example is Wifi 5 . Worked for me nicely on an old Galaxy S4, which highly preferred 2.4GHz WiFi if left alone. Some comments about the Wifi 5 program. 1. It's no...
by Jotne
Sun Jan 20, 2019 9:31 am
Forum: General
Topic: Mikrotik per user bandwidth volume consumption report
Replies: 10
Views: 424

Re: Mikrotik per user bandwidth volume consumption report

Look at my project (link in my signature) using Splunk to monitor various parameters from the Router.
One graph uses IP accounting to graph bandwidth used pr user.
There you can select all users, singel user, time period etc.
.
Treaffic.jpg
by Jotne
Sat Jan 19, 2019 9:28 pm
Forum: Beginner Basics
Topic: Whatsapp group mikrotik
Replies: 16
Views: 2027

Re: Whatsapp group mikrotik

@whitbread There has been times where I would try to help someone in a specific case, example on why they do not get Splunk to work (see my signature). Then there are no way we can get in contact without giving away private email or other information. Do you have any solution on that? PS we are far ...
by Jotne
Sat Jan 19, 2019 5:46 pm
Forum: General
Topic: SNMP Traps INFO
Replies: 2
Views: 266

Re: SNMP Traps INFO

If you can get it logged in the router, you can send it out using syslog.
Se my project (signature link) using Splunk to monitor MT Routers. Lots of the data is gotten from script sending out data using syslog.
by Jotne
Sat Jan 19, 2019 5:42 pm
Forum: Beginner Basics
Topic: Whatsapp group mikrotik
Replies: 16
Views: 2027

Re: Whatsapp group mikrotik

1. This crazy forum has no IM capability boooooo!!
100% agree

This forum is based on phpBB. It does have a simple message system so user can post to other user.
Its just a click for them to turn it on. Why they have turned it off I do not now. Hopefully they read this thread and enables it.
by Jotne
Sat Jan 19, 2019 10:04 am
Forum: Scripting
Topic: Auto Update Script
Replies: 1
Views: 114

Re: Auto Update Script

To disable a scheduler
/system scheduler set disabled=yes [find name=system_update on-even]
name= put the name of the scheduler to disable.
by Jotne
Sat Jan 19, 2019 9:56 am
Forum: General
Topic: Whatsapp video being blocked
Replies: 8
Views: 398

Re: Whatsapp video being blocked

@ariosvelez

Take a backup of your current config.
Reset router to default config.
If Whatsapp works, then you have a faulty configuration.
If it does not work, your IS block its.

As anav write, no need for special rules for Whatsapp
by Jotne
Sat Jan 19, 2019 9:53 am
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 345
Views: 55824

Re: v6.44beta [testing] is released!

With any communication you should not give away any information before login. If you look at forum.mikrotik.com it does use phpBB. On older version you could see at the bottom, what version it was. This was removed due to security and that hacker was target some specific version. As I did write in m...
by Jotne
Fri Jan 18, 2019 2:26 pm
Forum: Announcements
Topic: v6.44beta [testing] is released!
Replies: 345
Views: 55824

Re: v6.44beta [testing] is released!

Please remove OS version from telnet. It is not needed. I do use telnet to connect to Mikrotik Router using VPN connection. It does respond by telling both what it is and what version it has before you login. /system telnet 10.2.0.16 Trying 10.2.0.16... Connected to 10.2.0.16. Escape character is '^...
by Jotne
Fri Jan 18, 2019 8:37 am
Forum: General
Topic: Logstail.com : Graph and analyze our Mikrotik
Replies: 7
Views: 796

Re: Logstail.com : Graph and analyze our Mikrotik

Is this 100% free, if not what is the cost of it?
What about the security issue of sending all your log data unencrypted to a 3rd party site on the internet?
by Jotne
Fri Jan 18, 2019 8:29 am
Forum: Useful user articles
Topic: Using Splunk to analyse MikroTik logs 2.6 (Graphing everything)
Replies: 108
Views: 10570

Re: Using Splunk to analyse MikroTik logs 2.5 (Graphing everything)

No need to quote message above you, only part of it when needed. Always use Post Reply button under the post.

Are you 100% sure you have tagged the packet with MikroTik? There are no firewall?
Try in the search page and search for a star last 15 min. Do you get any?
*
by Jotne
Thu Jan 17, 2019 9:39 pm
Forum: Beginner Basics
Topic: How to shut down Router before Power Off?
Replies: 15
Views: 506

Re: How to shut down Router before Power Off?

i do agree that shutdown is the best way to do it.
But my guess is that more than 90% never does it.
by Jotne
Thu Jan 17, 2019 2:25 pm
Forum: RouterOS v7
Topic: v7 routeros
Replies: 12
Views: 994

Re: v7 routeros

路由器操作系統 7
by Jotne
Thu Jan 17, 2019 12:23 pm
Forum: Scripting
Topic: Mikrotik Auto Update Game ports for Online Games
Replies: 3
Views: 165

Re: Mikrotik Auto Update Game ports for Online Games

What type of game and for what port.
Some game may support uPnP, but that makes you net less secure.
by Jotne
Wed Jan 16, 2019 4:28 pm
Forum: Scripting
Topic: DynDns Script (No Logs)
Replies: 4
Views: 157

Re: DynDns Script (No Logs)

Not directly answer for you question, but why no use cloud service?
It will give you a free Mikrotik DNS name.
And if you still need your DynDNS name, point it to your MT cloud DNS.
Then all will update itself, no script needed.
by Jotne
Wed Jan 16, 2019 4:25 pm
Forum: Scripting
Topic: Mikrotik Auto Update Game ports for Online Games
Replies: 3
Views: 165

Re: Mikrotik Auto Update Game ports for Online Games

Not sure what you are looking for.
If you have a Minecraft server, you need to open just one port TCP/25565.
by Jotne
Wed Jan 16, 2019 8:59 am
Forum: General
Topic: Netflow packet analysis software for home network
Replies: 7
Views: 1056

Re: Netflow packet analysis software for home network

I do use Splunk to monitor my MikroTik Router. I have not implemented traffic flow (can be done) but du get traffic use from the router using IP accounting. See link in my signature. PS Splunk is free to use if you log less than 500MB/day. That should be enough for a very large home net. . Treaffic....
by Jotne
Tue Jan 15, 2019 2:54 pm
Forum: Scripting
Topic: netwatch script compose email to multiple recipients?
Replies: 7
Views: 7884

Re: netwatch script compose email to multiple recipients?

Smart workaround.

Why you can add multiple recipients for for CC and TO is strange. In normal email you can send to as meny TO users you like.
Also you need at list on TO user, also strange. Only CC should be enough as well.
Here MT has some work to do.
by Jotne
Tue Jan 15, 2019 12:15 pm
Forum: Scripting
Topic: Schedule shutdown of an interface
Replies: 1
Views: 89

Re: Schedule shutdown of an interface

Create a script with this line:
/interface ethernet set ether3 disabled=yes
schedule it to the time you like the if to go down.

Add another script with this line
/interface ethernet set ether3 disabled=no
and schedule it to come up at another time.
by Jotne
Mon Jan 14, 2019 8:48 am
Forum: Beginner Basics
Topic: Value use more than one script
Replies: 1
Views: 97

Re: Value use more than one script

You need to declare the global value in your script. Even if its used before.
:global currentTime
:log info $currentTime
by Jotne
Mon Jan 14, 2019 8:44 am
Forum: Beginner Basics
Topic: Priority-only VLAN tags (VLAN-ID 0)
Replies: 8
Views: 360

Re: Priority-only VLAN tags (VLAN-ID 0)

Why would you use VLAN-ID 0. I would not used that at the same time stay away from tagging VLAN-ID 1.
by Jotne
Mon Jan 14, 2019 8:31 am
Forum: General
Topic: Whatsapp video being blocked
Replies: 8
Views: 398

Re: Whatsapp video being blocked

I did have the same problem at my previous house. Whatsapp text and voice message worked fine, but no video call. It was my ISP that did block something. Changing location, all ok. Try to find what outging port that are needed. Some like this: TCP Ports; 80, 443, 4244, 5222, 5223, 5228, 5242, 50318,...
by Jotne
Sun Jan 13, 2019 10:13 am
Forum: Scripting
Topic: Suggestions for getting WAN IP from interface with multiple IPs
Replies: 7
Views: 259

Re: Suggestions for getting WAN IP from interface with multiple IPs

myip.opendns.com
Does not work, at leas for me for some reason
This works
http://whatismyip.com

But as I posted above, you can use the built in cloud function to get the IP.
by Jotne
Sat Jan 12, 2019 4:36 pm
Forum: Scripting
Topic: Suggestions for getting WAN IP from interface with multiple IPs
Replies: 7
Views: 259

Re: Suggestions for getting WAN IP from interface with multiple IPs

Ok I read it again, Suggestions for getting WAN IP from interface with multiple IPs I'm trying to get some DDNS updater scripts working, DDNS = Dynamic DNS https://en.wikipedia.org/wiki/Dynamic_DNS From what I do read. He need to get the public IP, the one that its routed to the internt, so that he ...
by Jotne
Sat Jan 12, 2019 10:54 am
Forum: Scripting
Topic: Suggestions for getting WAN IP from interface with multiple IPs
Replies: 7
Views: 259

Re: Suggestions for getting WAN IP from interface with multiple IPs

@Frostbyte Problem is that he try to update a DNS system, so you assume he has already a working DDNS, some he does not have. @naxxfish Have you looked at Cloud (IP->Cloud) on the Router? It's a free dynamic DNS updater from Miktrotik so you do not need other script. Try this to get public IP (This ...
by Jotne
Sat Jan 12, 2019 10:47 am
Forum: RouterOS v6 RC and v7 BETA
Topic: SNMP or lack of it
Replies: 2
Views: 284

Re: SNMP or lack of it

I do agree that SNMP does miss allot of function. But you can make your way around it. As long as you can see the data on the MT itself, you can send it out using script and syslog to send it out. I hva done this to get a various data from the MT to Splunk (syslog server). Se my signature link for m...
by Jotne
Thu Jan 10, 2019 7:56 pm
Forum: Announcements
Topic: v6.42.11 [long-term] is released!
Replies: 41
Views: 4722

Re: v6.42.11 [long-term] is released!

As I wrote before: ROS gives user all the possibilities to violate the regulations but it's entirely up to every user to understand when he is violating requlations and assume full responsibility for it. I do 100% agree with you, but some people has just used the setting that was there, maybe witho...
by Jotne
Thu Jan 10, 2019 8:13 am
Forum: General
Topic: Apple devices flooding DHCP server
Replies: 7
Views: 453

Re: Apple devices flooding DHCP server

@petterg This is how Apple devices work. I do guess that you have an open wifi network with a portal login? If so, all Apple devices that passing trough and see the open wifi network will try to connect to call home. I am in charge of a governmental guest network with around 4000-5000 wifi points. A...
by Jotne
Thu Jan 10, 2019 8:02 am
Forum: Announcements
Topic: v6.42.11 [long-term] is released!
Replies: 41
Views: 4722

Re: v6.42.11 [long-term] is released!

I seem to remember a few panicking posts in this forum, stating that Spain was about to ban certain type of Routerboards. And MT response was that they're gonna fix the problem. I have no problem with that, just not put a big change like this in a stable release. As we have seen here, several custo...
by Jotne
Wed Jan 09, 2019 10:26 pm
Forum: Scripting
Topic: Please help in writing the script.
Replies: 2
Views: 120

Re: Please help in writing the script.

Why?

It may be an other way to solve your problem.
by Jotne
Wed Jan 09, 2019 10:14 pm
Forum: Announcements
Topic: v6.42.11 [long-term] is released!
Replies: 41
Views: 4722

Re: v6.42.11 [long-term] is released!

superchannel is not removed.Country selection is to comply with regulations. If you want to break the law select superchannel, no country and keep using your link as before. When you see how much problem this gives and what a big change this is, it has nothing to do with an stable path, This is NOT...
by Jotne
Tue Jan 08, 2019 1:18 pm
Forum: General
Topic: Plink script
Replies: 7
Views: 413

Re: Plink script

/system upgrade;:put [get [find version = 6.42.10] status] This does not work for me, it gives red error after = due to the extra space after = . If I do remove the space, I do get this error: no such item What are you trying to do? Test what version you have? See if there are newer version? If you...
by Jotne
Tue Jan 08, 2019 12:28 am
Forum: General
Topic: Plink script
Replies: 7
Views: 413

Re: Plink script

In your example, “;” is still required at the end of the first line. It stands for “New Line.” Not true anymore "New Line" works nice. No need for ; anymore. Only if you like more commands on one line. https://wiki.mikrotik.com/wiki/Manual:Scripting The end of command line is represented by the tok...
by Jotne
Mon Jan 07, 2019 1:18 pm
Forum: Scripting
Topic: Syntax highlighting for Notepad++
Replies: 12
Views: 1074

Re: Syntax highlighting for Notepad++

@MT

Can you move this thread to this folder?
viewforum.php?f=23
(Make a ghost link back here)
by Jotne
Mon Jan 07, 2019 1:12 pm
Forum: General
Topic: VLAN is to complicated
Replies: 21
Views: 1270

Re: VLAN is to complicated

The document linked above wast posted in november due to this type of discussion. We did have a long thread on how to do VLAN and to clarify this MT did write this article.
by Jotne
Mon Jan 07, 2019 10:12 am
Forum: General
Topic: Router for traveling?
Replies: 4
Views: 299

Re: Router for traveling?

See this post for example setup, where a Router is used to connect to various Wifi network, then it uses NAT to and sends wifi out again on a different SSID. This could be used to connect to VPN as well. Any Wifi MT Router could do this. Chose your router from need of 2GHz, 5GHz, etc. https://forum....
by Jotne
Sat Jan 05, 2019 8:25 pm
Forum: General
Topic: Trying RB450Gx4 from HEX, VLAN Issues??
Replies: 5
Views: 322

Re: Trying RB450Gx4 from HEX, VLAN Issues??

Hi Jotne, I dont really see the point of posting two configs that I have already checked via notepadd ++ comparison but may concede LOL.
I did just reply on auto, was not awake :)
  • 1
  • 2
  • 3
  • 4
  • 5
  • 17