I see all the time ~3% "spi" usage in /tool profile on brand new CRS328-24P-4S+RM. Never saw this on rest of my devices before: CRS326-24G, CRS317, CCR2004, RB4011, ... so I'm just curious what is causing this. If "spi" is related to internal flash, from my point of view this should not happen on simple L2 switch with almost zero flash writes.

Currently there is only one PoE device connected:
> /interface ethernet poe monitor ether21
             name: ether21
          poe-out: auto-on
      poe-voltage: auto
   poe-out-status: powered-on
  poe-out-voltage: 52.3V
  poe-out-current: 94mA
    poe-out-power: 4.9W
System info:
> /system routerboard print
       routerboard: yes
             model: CRS328-24P-4S+
          revision: r2
     serial-number: <REMOVED>
     firmware-type: dx3230L
  factory-firmware: 6.47.6
  current-firmware: 6.47.9
  upgrade-firmware: 6.47.9
Switch config:
/interface bridge
add admin-mac=<REMOVED> auto-mac=no name=bridge1 priority=0x5000 vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] disabled=yes
set [ find default-name=ether2 ] poe-out=off
set [ find default-name=ether3 ] disabled=yes poe-out=off
set [ find default-name=ether4 ] disabled=yes poe-out=off
set [ find default-name=ether5 ] poe-out=off
set [ find default-name=ether6 ] disabled=yes poe-out=off
set [ find default-name=ether7 ] poe-out=off
set [ find default-name=ether8 ] poe-out=off
set [ find default-name=ether9 ] poe-out=off
set [ find default-name=ether10 ] poe-out=off
set [ find default-name=ether11 ] poe-out=off
set [ find default-name=ether12 ] poe-out=off
set [ find default-name=ether13 ] disabled=yes poe-out=off
set [ find default-name=ether14 ] disabled=yes poe-out=off
set [ find default-name=ether15 ] poe-out=off
set [ find default-name=ether16 ] disabled=yes poe-out=off
set [ find default-name=ether17 ] disabled=yes poe-out=off
set [ find default-name=ether18 ] disabled=yes poe-out=off
set [ find default-name=ether19 ] disabled=yes poe-out=off
set [ find default-name=ether20 ] disabled=yes poe-out=off
set [ find default-name=ether21 ]
set [ find default-name=ether22 ] disabled=yes poe-out=off
set [ find default-name=ether23 ] poe-out=off
set [ find default-name=ether24 ] disabled=yes poe-out=off
set [ find default-name=sfp-sfpplus1 ]
set [ find default-name=sfp-sfpplus2 ]
set [ find default-name=sfp-sfpplus3 ] disabled=yes
set [ find default-name=sfp-sfpplus4 ] disabled=yes
/interface vlan
add interface=bridge1 name=bridge1-vlan666 vlan-id=666
add interface=bridge1 name=bridge1-vlan1501 vlan-id=1501
/interface bonding
add down-delay=100ms lacp-rate=1sec min-links=1 mode=802.3ad name=bonding1 slaves=sfp-sfpplus1,sfp-sfpplus2 transmit-hash-policy=layer-2-and-3 up-delay=100ms
add down-delay=100ms lacp-rate=1sec min-links=1 mode=802.3ad name=bonding2 slaves=ether9,ether10,ether11,ether12 transmit-hash-policy=layer-2-and-3 up-delay=100ms
/interface list
/snmp community
set [ find default=yes ] disabled=yes
add addresses=<REMOVED> name=<REMOVED>
add addresses=<REMOVED> name=<REMOVED>
/interface bridge filter
add action=drop chain=output out-interface=ether23 src-mac-address=<REMOVED>/FF:FF:FF:FF:FF:FF
/interface bridge port
add bridge=bridge1 interface=ether1 learn=yes pvid=100
add bridge=bridge1 interface=ether2 learn=yes pvid=666
add bridge=bridge1 interface=ether3 learn=yes
add bridge=bridge1 interface=ether4 learn=yes
add bridge=bridge1 interface=ether5 learn=yes pvid=100
add bridge=bridge1 interface=ether6 learn=yes
add bridge=bridge1 interface=ether7 learn=yes
add bridge=bridge1 interface=ether8 learn=yes
add bridge=bridge1 interface=ether13 learn=yes
add bridge=bridge1 interface=ether14 learn=yes
add bridge=bridge1 interface=ether15 learn=yes
add bridge=bridge1 interface=ether16 learn=yes
add bridge=bridge1 interface=ether17 learn=yes
add bridge=bridge1 interface=ether18 learn=yes
add bridge=bridge1 interface=ether19 learn=yes
add bridge=bridge1 interface=ether20 learn=yes
add bridge=bridge1 interface=ether21 learn=yes
add bridge=bridge1 interface=ether22 learn=yes
add bridge=bridge1 interface=ether23 learn=yes pvid=1001
add bridge=bridge1 interface=ether24 learn=yes
add bridge=bridge1 interface=bonding1 learn=yes
add bridge=bridge1 interface=bonding2 learn=yes
/ip neighbor discovery-settings
set discover-interface-list=MANAGEMENT
/interface bridge vlan
add bridge=bridge1 tagged=bonding2,ether15,bonding1,ether21 untagged=ether5 vlan-ids=100
add bridge=bridge1 tagged=bonding2,ether15,ether5,bonding1,ether21 vlan-ids=101
add bridge=bridge1 tagged=bonding2,ether15,ether5,bridge1,bonding1,ether21,sfp-sfpplus2 untagged=ether2 vlan-ids=666
add bridge=bridge1 tagged=bonding2,ether15,bonding1,ether21 vlan-ids=999
add bridge=bridge1 tagged=bonding2,ether15,bonding1 untagged=ether23 vlan-ids=1001
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=1002
add bridge=bridge1 tagged=bonding2,ether15,bridge1,bonding1,ether21,sfp-sfpplus2 untagged=ether7 vlan-ids=1501
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=2001
add bridge=bridge1 tagged=bonding2,ether15,ether5,bonding1 vlan-ids=2003
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=3001
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=3002
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=3003
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=3004
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=3005
add bridge=bridge1 tagged=bonding2,ether15,bonding1 vlan-ids=3101
/interface ethernet switch rule
add  new-vlan-id=1501 ports=ether7 src-mac-address=<REMOVED>/FF:FF:FF:FF:FF:FF switch=switch1 vlan-header=not-present
/interface list member
add interface=bridge1-vlan1501 list=MANAGEMENT
add interface=bridge1-vlan666 list=MANAGEMENT
/ip address
add address=<REMOVED> disabled=yes interface=bridge1-vlan666 network=<REMOVED>
add address=<REMOVED> interface=bridge1-vlan1501 network=<REMOVED>
/ip cloud
set update-time=no
/ip dns
set cache-max-ttl=5m servers=<REMOVED>
/ip route
add distance=1 gateway=<REMOVED>
add distance=1 dst-address=<REMOVED> gateway=<REMOVED>
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www-ssl certificate=<REMOVED> disabled=no tls-version=only-1.2
set api disabled=yes
set api-ssl certificate=<REMOVED> disabled=yes tls-version=only-1.2
/ip ssh
set always-allow-password-login=yes strong-crypto=yes
set enabled=yes location=<REMOVED> trap-generators=""
/system identity
set name=<REMOVED>
/system ntp client
set enabled=yes primary-ntp=<REMOVED>
/system package update
set channel=long-term
/system routerboard settings
set boot-os=router-os silent-boot=yes
/tool mac-server
set allowed-interface-list=MANAGEMENT
/tool mac-server mac-winbox
set allowed-interface-list=MANAGEMENT
/tool romon
set enabled=yes
/tool romon port
add disabled=no forbid=yes interface=ether23


