My logs show my WAN link went down last night, then came straight back up, then the next 5 entries are as follows.
“system, info MikroTik1: item removed”
“system, info MikroTik1: item removed”
“system, info MikroTik1: item added”
“system, info MikroTik1: item added”
“system, info MikroTik1: item added”
Normally It would show something like below, this looks like the system itself was removing and adding items, is this normal?
“system, info, account MikroTik1: user admin logged in from ... via winbox”
“system, info MikroTik1: log action changed by admin”
“system, info, account MikroTik1: user admin logged out from ... via winbox”
this is not normal. You can use remote syslog and should review log everyday. you don’t use close service. (Ssh, api, api-ssl, telnet etc) and define the absolute MAC address for winbox or ssh etc remote access. for example
It is the 5 entries at the top that are not the normal ones, the ones showing my admin login are genuine and are from the log rule created in the firewall which is directed to a remote machine running Syslog Watcher Pro.
The router seems to have done something by itself that was logged and sent to Syslog Watcher Pro
Very strange as there is no login associated with the changes, I do not no if it is connected to the changes but it is no longer working as it has been for almost 12 months, even restoring from a backup does not help.