Skip to content

FAQ

Each answer is the short form of a page that has the detail, and links to it.

mikroscope does not run on MIPS or TILE routers. The agent runs in a RouterOS container, and MikroTik ships the container package for arm, arm64, x86 and CHR only (MikroTik’s package list). mikroscope builds its agent for arm64, arm and x86_64. On a MIPS or TILE board, SNMP or an API exporter is the tool: When to use another tool.

Tested on lists every device and RouterOS version mikroscope has run on, physical and virtual, with what ran on each and what has not been tested. A board report from another router adds it there.

The container step writes privileged=, an attribute RouterOS added in 7.24, whatever --privileged says. doctor and the install script check the version first and stop on an earlier release with nothing written: Requirements.

MikroTik built it that way. Device-mode limits what a router allows, to protect it from an attacker who gained access, so changing it takes physical access: after /system/device-mode/update container=yes, someone presses the reset or mode button, or power-cycles the router, within five minutes (MikroTik’s device-mode page). No tool can do it remotely: Device mode.

At the install default of 10 Hz the agent costs 2.69 % of one core and 13.2 MiB of memory, read from its own cgroup, and 16.83 % at 100 Hz. That is over the project’s own CPU budget of 2 % and inside its memory budget of 16 MiB: Agent cost, with how to measure it on your router.

The agent never connects out and presents no credential. Every write is listed before it is made and tagged, and uninstall removes everything the install created and verifies that nothing is left: a scripted round trip left the router’s /export byte-identical (verified). The container runs privileged=yes, a real grant: Security model.

Not from inside the container. /proc/net/dev and the other network files are per network namespace, so there they count the container’s own veth, and privileged=yes does not change that. Per-interface bytes and packets come from the RouterOS API, which the collector merges on the agent’s clock: Container visibility.

About one second. RouterOS cpu-load tracks a trailing mean of about a second of the kernel’s busy time, reaches the API a fraction of a second late, and is not a sixty-second average (measured). A burst shorter than that second is averaged into it: RouterOS API tier.

mikroscope does not replace SNMP or mktxp. It does not replace the RouterOS API either, and takes per-interface traffic from it. What it adds is the kernel’s own view, which none of the others is documented to read: per-core ticks at up to 100 Hz, softirqs, softnet drops and squeezes, and the kernel log. Where no container runs, SNMP or mktxp is the tool: Compared with alternatives.

install does not set up Grafana: it writes only to the router. The collector does, when it runs with --grafana <url> and a Grafana service-account token in GRAFANA_TOKEN: at every start it creates or corrects the datasource and publishes the dashboard of each store it can describe: InfluxDB, Elasticsearch and PostgreSQL (through --postgres) on their own, Prometheus and Graphite once given the address in --grafana-datasource-url. mikroscope dashboards publish, given the collector’s sink flags and --grafana, does the same once without collecting, and dashboards import or Grafana’s own import binds a dashboard to a datasource you already have: Set up in Grafana.

The agent sends nothing off the router. It serves HTTP on its veth address and makes no outbound connection, and there is no update check. Your collector pulls from it, and every sink token and API credential stays on your host, because whatever sits in the container’s envlist is treated as readable by every RouterOS user with read: Security model.