Home / Blog / MikroTik SIEM
firewall

Connecting MikroTik Syslog to SIEM: Step-by-Step Setup

RouterOS syslog settings, firewall filter logs and connection to OxiSec in 15 minutes.

K
Kerem M.

MikroTik devices are common in Türkiye. If RouterOS logs are not configured correctly, they will either not come to SIEM at all or they will come with noise.

1. Remote syslog address

/system logging action
add name=oxisec remote=SIEM_IP remote-port=5514 target=remote

2. Which topics?

3. On the SIEM side

OxiSec MikroTik parser automatically extracts action, src/dst IP and interface fields. Port scan and SSH brute force preset rules are ready.

💡
Tenant mapping for internal IPs behind NAT from documentation check.

Analyze your logs with OxiSec

Installation in 15 minutes · community plan is free

Start Free →