MikroTik RouterOS: send syslog, Traffic Flow and SNMP traps to MobiObs

Updated 28 September 2026

RouterOS can send its logs to a remote syslog server on any port and export Traffic Flow (NetFlow v9 or IPFIX), which covers most of what you need from a MikroTik on site. SNMP traps are the exception, because RouterOS does not let you choose the trap port; this guide explains the workaround.

MobiObs is not released yet. It is coming to Google Play first, then the App Store and desktop. Join the launch list to get one email when it is available.

Before you start

The MobiObs device is 10.20.4.9 in the examples, and 192.0.2.3 is an address on the router. MobiObs listens on udp/5514 for syslog, udp/2055 for NetFlow and IPFIX and udp/1162 for SNMP traps. Mobile operating systems do not let apps listen on ports below 1024.

Commands are for RouterOS v7 in the terminal (or the same fields in WinBox). Most also work on v6, and differences are noted. Property names change between releases more often than on other platforms, so if a command is rejected, press Tab to see the properties your version accepts.

Syslog

RouterOS logging has two parts: an action that says where to send messages, and rules that say which topics go to that action.

RouterOS v6 / v7: remote logging to udp/5514

/system logging action add name=mobiobs target=remote remote=10.20.4.9 \
    remote-port=5514 src-address=192.0.2.3 bsd-syslog=yes syslog-facility=local0
/system logging add topics=info action=mobiobs
/system logging add topics=warning action=mobiobs
/system logging add topics=error action=mobiobs
/system logging add topics=critical action=mobiobs

bsd-syslog=yes sends standard RFC 3164 messages with a priority, timestamp and hostname header. Leave it on: the standard header is what lets MobiObs file each message under the right host, facility and severity. Recent v7 releases add further format and transport options on the remote action (including RFC 5424 and TCP); check with Tab whether your version has them before using them.

To follow a specific problem, add rules for single topics such as topics=dhcp, topics=wireless, topics=ipsec or topics=firewall. Firewall rules with log=yes write to the firewall topic, which is a simple way to see dropped traffic in MobiObs. Debug topics can be very verbose, so enable them only briefly.

Traffic Flow (NetFlow v9 and IPFIX)

RouterOS v7: Traffic Flow to udp/2055

/ip traffic-flow set enabled=yes interfaces=all \
    active-flow-timeout=1m inactive-flow-timeout=15s
/ip traffic-flow target add dst-address=10.20.4.9 port=2055 version=9

Use version=ipfix for IPFIX; MobiObs decodes v5, v9 and IPFIX on the same port, but v9 or IPFIX carry more fields than v5. interfaces=all is the simplest choice; list specific interfaces (for example interfaces=ether1) on a busy router to limit load. Older RouterOS releases wrote the destination as a single address=10.20.4.9:2055 property instead of dst-address and port.

RouterOS routers do not export sFlow. Some MikroTik switch models have sFlow support in their switch-chip configuration, but it depends on the model and version, so check the documentation for your hardware if you need it.

SNMP traps

RouterOS v7: SNMPv2c traps

/snmp community add name=MOBIOBS-RO addresses=10.20.4.9/32
/snmp set enabled=yes trap-community=MOBIOBS-RO trap-version=2 \
    trap-target=10.20.4.9 trap-generators=interfaces trap-interfaces=all

For SNMPv3 traps, set trap-version=3 and give the community an authentication and encryption configuration (security=private, authentication-protocol, authentication-password, encryption-protocol, encryption-password), then add a matching SNMPv3 user in MobiObs. Check the protocol names your version offers.

The port limitation. As far as we know, RouterOS always sends traps to udp/162 and has no option for the trap destination port. A mobile device cannot listen on 162, so traps need to be redirected on the way:

  • Destination NAT on another router in the path. Translate udp/162 from the MikroTik's address to 10.20.4.9 udp/1162. This keeps the original source address, so MobiObs shows the MikroTik as the agent.
  • A relay on a Linux host. Run snmptrapd listening on udp/162 with authCommunity log,net MOBIOBS-RO and forward default udp:10.20.4.9:1162 in snmptrapd.conf (the net permission is what allows forwarding). The relay becomes the source address, and v2c traps then appear to come from it.

RouterOS also raises relatively few trap types (interface state changes and a small number of others), so syslog is usually the more useful signal from a MikroTik.

Verify on the device

RouterOS: checks

/system logging action print where name=mobiobs
/system logging print where action=mobiobs
/ip traffic-flow print
/ip traffic-flow target print
/snmp print
:log info "MobiObs test from RouterOS"

The :log info line writes a message to the info topic, so it should appear in MobiObs straight away. To see packets leaving the router, use /tool sniffer quick ip-address=10.20.4.9. If they leave but do not arrive, see the troubleshooting checklist.

Remove it afterwards

RouterOS: clean-up

/system logging remove [find action=mobiobs]
/system logging action remove [find name=mobiobs]
/ip traffic-flow target remove [find dst-address=10.20.4.9]
/ip traffic-flow set enabled=no
/snmp set trap-target="" trap-generators=""
/snmp community remove [find name=MOBIOBS-RO]

Remove the logging rules before the action, because RouterOS will not delete an action that rules still use. Only disable Traffic Flow or SNMP if they were off before your visit; /export taken beforehand is the easiest record of the original state.