FlowPro NG — SIEM platform with native MikroTik support

Hi everyone, wanted to share a project we've been working on that might be useful for MikroTik users.

FlowPro NG is an on-premises SIEM (Security Information and Event Management) platform built with MikroTik networks in mind.

MikroTik integration:

  • Native NetFlow v5/v9 collector — just point your /ip traffic-flow target at FlowPro and it works instantly
  • RouterOS syslog parsing out of the box — firewall logs, DHCP leases, wireless events, all parsed and searchable
  • Automatic MikroTik device recognition
  • Works with all RouterOS devices (hAP, hEX, CCR, CRS, CHR...)

What else it does:

  • Real-time traffic analytics with geo maps, top talkers, per-protocol breakdown
  • Suricata IDS with automatic MITRE ATT&CK mapping
  • CVE vulnerability database (333,000+ entries with EPSS risk scoring)
  • SSL/TLS certificate monitoring
  • Honeypot management (17 types)
  • Asset management with automatic device discovery
  • NIS2 compliance reporting
  • AI-powered log analysis

Setup:
Single Ubuntu server, one-command install. MikroTik side is just two lines:
/ip traffic-flow set enabled=yes interfaces=all
/ip traffic-flow target add dst-address= port=2055 version=9

Pricing:
Free tier available (5 agents, 1 flow source). Paid plans start at €99/month. 14-day Enterprise trial with no credit card required.

More info: www.flowpro.eu

Happy to answer any questions about the MikroTik integration or the platform in general.

2 Likes

Interesting, a lot of cloud data is collected this way.

I wonder how much they pay the cloud owner when they resell it?

What an idiot, I should have read better...

Maybe stupid question, but what would a Mikrotik network administrator do with 336,626 CVE's (or 1,385 last week)?

Maybe there should be a filter of sorts showing only the Mikrotik related ones?

Or a multiple choice one, with 4-5 manufacturers selectable for "mixed brand" networks?

It doesn't make sense, unless the analyzed data reveals vulnerabilities detected just by looking at the flow...

Claude vibe-code? :slight_smile:

1 Like

Great question! But there's a fundamental misunderstanding here — FlowPro doesn't collect or resell any data. It's the exact opposite.

FlowPro is a 100% on-premise SIEM/NTA solution. All data stays on the customer's own hardware. The customer owns their data completely.

1 Like

You can you use “CVE Databases / Watchlist” only for interested topics and manufacturers:-) You can check it at https://demo.flowpro.eu

I have to apologize to you, it's my fault I read it wrong, and it even is wroted!

1 Like