Skip to content

Glossary

One sentence per term, in the sense these pages use it, each linked to the page that explains it in full; a kernel term also links the kernel’s own documentation.

The part of the collector that holds a session to the RouterOS binary API and reads what the container cannot see, above all per-interface bytes and packets, set by --api-mode off, slow or full: the RouterOS API tier.

One core’s busy ticks divided by all of its ticks in one sample, capped at 1 where it is derived, while the ticks themselves ship raw: ticks, not time.

The full-rate samples the agent keeps around the moment a trigger condition fired, from its default set or from the one given with --triggers, 5 s either side by default, fetched afterwards over HTTP: triggered capture.

mikroscope forward on your host, which pulls the agent’s ring, samples the API tier, runs the derive stage and writes the merged timeline to every sink you name: the collector.

Linux’s connection-tracking table, whose nf_conntrack_count inside the container counts only the container’s own connections, so the agent takes the router’s count from the nf_conntrack slab under privileged=yes: conntrack without the API.

The CPU figure RouterOS’s /system/resource reports for all cores combined, a trailing mean of about one second: how many seconds it averages over.

The step in the collector that computes values beside each kernel sample and each counter poll, such as mem_pressure, packets_per_irq and burst, and runs the detection rules: what the collector derives.

A discrete event the collector puts on the timeline when one of its eleven rules fires, a “look here” rather than a verdict: detections.

The RouterOS setting that limits which features a router allows, where container=yes turns containers on and, by MikroTik’s design, takes a button press or a cold reboot to confirm: device-mode container=yes.

The real length of a sample’s interval in nanoseconds, shipped beside the raw ticks so that whoever reads them divides over the time that actually elapsed: a sample line.

A named list of environment variables under RouterOS’s /container/envs that a container starts with (MikroTik’s container page), where install writes the agent’s configuration, its ownership marker and no credential but the optional token: what the envlist carries.

The slower cadence a level source is read or stored at, set per source for a reason the agent names on /capabilities, never applied to a counter, and turned off everywhere by FLOOR_HZ: each source at its own floor.

A run of samples the agent no longer holds when a reader asks for them, reported with the sequence numbers lost and never filled in: how far back the agent remembers.

Instructions per cycle, from the PMU’s instructions and cycles counts, which the agent ships raw without dividing and the collector’s ipc-collapse detection watches: the one source beneath the tick.

The agent’s samples of the router’s kernel as the collector pulls them, on whose clock the API tier is stamped: what one run does.

The agent’s source for /dev/kmsg, the kernel’s own log buffer (kernel ABI documentation), drained every tick under privileged=yes and carrying lines RouterOS’s own log does not show: a loop only the kernel could see.

A timestamped note in a recording, typed into record, added with mark or taken from the router’s own log, which plot draws on the chart: markers, and whose clock they are in.

The CPU’s performance monitoring unit, read through perf_event_open as the agent’s perf source, counting cycles, instructions, cache and branch events per core beneath the tick and only under privileged=yes: the one source beneath it.

The container setting privileged=yes, which RouterOS has from 7.24 and which drops the container’s user namespace so the kernel log, /proc/slabinfo, the MTD ECC counters and the PMU become readable without widening its network or PID namespace: what privileged buys.

Pressure stall information, the share of time tasks stalled waiting for CPU, memory or I/O, in /proc/pressure (kernel documentation), which the agent reads where a kernel has it and some RouterOS kernels do not: no finer clock from the kernel.

The transport that pulls the agent’s ring through the router itself, running /tool fetch over the RouterOS binary API, for a host that cannot route to the veth: relay, through the RouterOS API.

The agent’s in-memory buffer of the last --buffer seconds of samples, 60 s by default, beyond which nothing exists on the router: how far back the agent remembers.

MikroTik’s implementation of Linux containers in the container package (MikroTik’s container page), which shares the router’s kernel, so /proc inside it is the router’s own except for the per-namespace network files: the router’s CPU, the container’s network.

/proc/schedstat, the scheduler’s per-CPU counts of time spent running and waiting to run (kernel documentation), absent from some RouterOS kernels and read where present: no finer clock from the kernel.

A container whose image starts from nothing (Docker’s scratch), which for the agent is one static binary and nothing else, as Dockerfile.agent says: what runs where.

A destination the collector writes to, one of eleven that run from a file and standard output to Prometheus, InfluxDB 3 and PostgreSQL: the eleven sinks.

/proc/slabinfo, the kernel allocator’s caches and how many objects each holds (slabinfo(5)), global and root-only, so the agent reads it under privileged=yes: what privileged buys.

The kernel’s deferred interrupt work, network receive and timers among it, counted per CPU and per type in /proc/softirqs (kernel documentation) and shipped per core by the agent: receive path and interrupts.

The kernel’s per-CPU queues of incoming packets, whose /proc/net/softnet_stat counts packets processed, dropped and squeezed per CPU and stays the router’s even inside the container: CPU and memory are the router’s.

The comment mikroscope:<name> (managed by mikroscope) that install writes on every object that takes a comment, and as MIKROSCOPE_TAG in the envlist, by which removal selects and never by pattern: how ownership is decided.

Two things on this site: the kernel’s unit of CPU time in /proc/stat, one USER_HZ period of 10 ms, and one turn of the agent’s sampler at its configured rate: ticks, not time.

The softnet counter of times the receive softirq ran out of budget with packets still queued, nonzero even on an idle router and worth watching when it rises with flat throughput: a packet flood.

The unit /proc/stat counts CPU time in (kernel documentation), one tick of 10 ms at the usual USER_HZ of 100, which sets the finest CPU step any reader of that file can see: ticks, not time.

A virtual Ethernet interface (veth(4)) joining the container to the router, which install creates as veth-mikroscope on a /30 with the router on .1 and the agent on .2, the only address the agent listens on: the objects and their defaults.