RadiusNest › Guides

MikroTik remote syslog: keep router logs on another machine

Last updated: 11 October 2026

The MikroTik log lives in memory and keeps only the last thousand lines. After a reboot, or a busy evening, the line you needed is gone. Sending the log to a syslog server keeps it for as long as you want.

1. Where to send it

/system logging action set [find name=remote] remote=192.168.88.10 remote-port=514

RouterOS already has a logging action named remote; this points it at your server. 192.168.88.10 is the machine that will store the logs. Keep it on your own network; avoid sending logs across the open internet.

2. What to send

/system logging add topics=info action=remote
/system logging add topics=warning action=remote
/system logging add topics=error action=remote
/system logging add topics=critical action=remote

This copies the same messages you see in the normal log. Add specific topics when you need them:

/system logging add topics=hotspot,!debug action=remote
/system logging add topics=pppoe,!debug,!packet action=remote
/system logging add topics=account action=remote

!debug leaves out the very detailed messages of that topic; account records who logged in to the router. Avoid debug topics on a busy router; they produce a lot.

3. Log firewall drops (optional)

Add log=yes and a prefix to a rule to log what it catches:

/ip firewall filter set [find comment="max 200 TCP connections per user"] log=yes log-prefix="CONNLIMIT"

(That is the connection limit from limiting torrents.) A rule with several topics, such as topics=hotspot,info, logs only messages that carry all of them; use one rule per topic to log either. Only log rules that match rarely. Logging every packet of a busy rule fills the server and costs CPU.

4. The receiving server

On a Linux machine with rsyslog, allow UDP syslog by adding these lines to /etc/rsyslog.conf and restarting rsyslog:

module(load="imudp")
input(type="imudp" port="514")

Messages arrive in the system log; with a filter rule rsyslog can write each router to its own file. On Windows, any syslog server program works the same way. Open UDP 514 on the server's firewall for your routers only.

Correct time

Logs are only useful with the right time on them. Set NTP on every router.

Without a server: log to the router's disk

/system logging action set [find name=disk] disk-file-name=log disk-lines-per-file=1000 disk-file-count=5
/system logging add topics=critical action=disk
/system logging add topics=error action=disk

Disk logs survive a reboot, but flash memory wears out if you write a lot to it. Keep disk logging to important topics.

Check

Make a test message and look for it on the server:

:log info "syslog test from router"

Questions and answers

Which port does MikroTik remote syslog use?

UDP 514 by default; you can set remote-port in the logging action.

Why does the MikroTik log disappear after a reboot?

The normal log is kept in memory. Send it to a syslog server or log important topics to disk.

Can I log hotspot and PPPoE logins to syslog?

Yes. Add logging rules for the hotspot and pppoe topics with the remote action.

Related guides

Start the free trial See pricing