MikroTik remote syslog: keep router logs on another machine
Last updated: 11 October 2026
The MikroTik log lives in memory and keeps only the last thousand lines. After a reboot, or a busy evening, the line you needed is gone. Sending the log to a syslog server keeps it for as long as you want.
1. Where to send it
/system logging action set [find name=remote] remote=192.168.88.10 remote-port=514RouterOS already has a logging action named remote; this points it at your server. 192.168.88.10 is the machine that will store the logs. Keep it on your own network; avoid sending logs across the open internet.
2. What to send
/system logging add topics=info action=remote
/system logging add topics=warning action=remote
/system logging add topics=error action=remote
/system logging add topics=critical action=remoteThis copies the same messages you see in the normal log. Add specific topics when you need them:
/system logging add topics=hotspot,!debug action=remote
/system logging add topics=pppoe,!debug,!packet action=remote
/system logging add topics=account action=remote!debug leaves out the very detailed messages of that topic; account records who logged in to the router. Avoid debug topics on a busy router; they produce a lot.
3. Log firewall drops (optional)
Add log=yes and a prefix to a rule to log what it catches:
/ip firewall filter set [find comment="max 200 TCP connections per user"] log=yes log-prefix="CONNLIMIT"(That is the connection limit from limiting torrents.) A rule with several topics, such as topics=hotspot,info, logs only messages that carry all of them; use one rule per topic to log either. Only log rules that match rarely. Logging every packet of a busy rule fills the server and costs CPU.
4. The receiving server
On a Linux machine with rsyslog, allow UDP syslog by adding these lines to /etc/rsyslog.conf and restarting rsyslog:
module(load="imudp")
input(type="imudp" port="514")Messages arrive in the system log; with a filter rule rsyslog can write each router to its own file. On Windows, any syslog server program works the same way. Open UDP 514 on the server's firewall for your routers only.
Correct time
Logs are only useful with the right time on them. Set NTP on every router.
Without a server: log to the router's disk
/system logging action set [find name=disk] disk-file-name=log disk-lines-per-file=1000 disk-file-count=5
/system logging add topics=critical action=disk
/system logging add topics=error action=diskDisk logs survive a reboot, but flash memory wears out if you write a lot to it. Keep disk logging to important topics.
Check
Make a test message and look for it on the server:
:log info "syslog test from router"
Questions and answers
Which port does MikroTik remote syslog use?
UDP 514 by default; you can set remote-port in the logging action.
Why does the MikroTik log disappear after a reboot?
The normal log is kept in memory. Send it to a syslog server or log important topics to disk.
Can I log hotspot and PPPoE logins to syslog?
Yes. Add logging rules for the hotspot and pppoe topics with the remote action.