Its better to get the logs out of the router. For example, see my MikroTik for Splunk here:
http://forum.mikrotik.com/t/tool-using-splunk-to-analyse-mikrotik-logs-4-0-graphing-everything/153043/1