FAQ
Each answer is the short form of a page that has the detail, and links to it.
MIPS and TILE
Section titled “MIPS and TILE”mikroscope does not run on MIPS or TILE routers. The agent runs in a RouterOS container, and MikroTik
ships the container package for arm, arm64, x86 and CHR only (MikroTik’s package
list). mikroscope builds its
agent for arm64, arm and x86_64. On a MIPS or TILE board, SNMP or an API exporter is the tool:
When to use another tool.
Tested routers
Section titled “Tested routers”Tested on lists every device and RouterOS version mikroscope has run on, physical and virtual, with what ran on each and what has not been tested. A board report from another router adds it there.
Why RouterOS 7.24
Section titled “Why RouterOS 7.24”The container step writes privileged=, an attribute RouterOS added in 7.24, whatever
--privileged says. doctor and the install script check the version first and stop on an
earlier release with nothing written:
Requirements.
Device-mode button
Section titled “Device-mode button”MikroTik built it that way. Device-mode limits what a router allows, to protect it from an
attacker who gained access, so changing it takes physical access: after /system/, someone presses the reset or mode button, or power-cycles the router, within five
minutes (MikroTik’s device-mode
page). No tool can do it
remotely: Device mode.
Router cost
Section titled “Router cost”At the install default of 10 Hz the agent costs 2.69 % of one core and 13.2 MiB of memory, read from its own cgroup, and 16.83 % at 100 Hz. That is over the project’s own CPU budget of 2 % and inside its memory budget of 16 MiB: Agent cost, with how to measure it on your router.
Production use
Section titled “Production use”The agent never connects out and presents no credential. Every write is listed before it is made
and tagged, and uninstall removes everything the install created and verifies that nothing is
left: a scripted round trip left the router’s /export byte-identical
(verified). The container runs privileged=yes, a real
grant: Security model.
Interface traffic
Section titled “Interface traffic”Not from inside the container. /proc/net/dev and the other network files are per network
namespace, so there they count the container’s own veth, and privileged=yes does not change
that. Per-interface bytes and packets come from the RouterOS API, which the collector merges on the
agent’s clock:
Container visibility.
cpu-load window
Section titled “cpu-load window”About one second. RouterOS cpu-load tracks a trailing mean of about a second of the kernel’s busy
time, reaches the API a fraction of a second late, and is not a sixty-second average
(measured). A burst shorter than that second
is averaged into it: RouterOS API
tier.
SNMP and mktxp
Section titled “SNMP and mktxp”mikroscope does not replace SNMP or mktxp. It does not replace the RouterOS API either, and takes per-interface traffic from it. What it adds is the kernel’s own view, which none of the others is documented to read: per-core ticks at up to 100 Hz, softirqs, softnet drops and squeezes, and the kernel log. Where no container runs, SNMP or mktxp is the tool: Compared with alternatives.
Grafana dashboards
Section titled “Grafana dashboards”install does not set up Grafana: it writes only to the router. The collector does, when it runs
with --grafana <url> and a Grafana service-account token in GRAFANA_TOKEN: at every start it
creates or corrects the datasource and publishes the dashboard of each store it can describe:
InfluxDB, Elasticsearch and PostgreSQL (through --postgres) on their own, Prometheus and Graphite
once given the address in --grafana-datasource-url.
mikroscope dashboards publish, given the collector’s sink flags and --grafana, does the same
once without collecting, and dashboards import or Grafana’s own import binds a dashboard to a
datasource you already have: Set up in Grafana.
Outbound connections
Section titled “Outbound connections”The agent sends nothing off the router. It serves HTTP on its veth address and makes no outbound
connection, and there is no update check. Your collector pulls from it, and every sink token and
API credential stays on your host, because whatever sits in the container’s envlist is treated as
readable by every RouterOS user with read: Security model.