# FAQ

Short answers about mikroscope on MikroTik RouterOS, from MIPS and the 7.24 minimum to cost, production use, cpu-load and the Grafana dashboards, each linked to the page with the detail.

Source: https://jmrplens.github.io/mikroscope/start/questions/

Each answer is the short form of a page that has the detail, and links to it.

## MIPS and TILE

mikroscope does not run on MIPS or TILE routers. The agent runs in a RouterOS container, and MikroTik
ships the `container` package for arm, arm64, x86 and CHR only ([MikroTik's package
list](https://help.mikrotik.com/docs/spaces/ROS/pages/40992872/Packages)). mikroscope builds its
agent for arm64, arm and x86_64. On a MIPS or TILE board, SNMP or an API exporter is the tool:
[When to use another tool](https://jmrplens.github.io/mikroscope/start/compared/#when-not-to-use-mikroscope).

## Tested routers

[Tested on](https://jmrplens.github.io/mikroscope/about/status/) lists every device and RouterOS version mikroscope has run
on, physical and virtual, with what ran on each and what has not been tested. A
[board report](https://github.com/jmrplens/mikroscope/issues/new?template=2-board-report.yml) from
another router adds it there.

## Why RouterOS 7.24

The container step writes `privileged=`, an attribute RouterOS added in 7.24, whatever
`--privileged` says. `doctor` and the install script check the version first and stop on an
earlier release with nothing written:
[Requirements](https://jmrplens.github.io/mikroscope/install/prerequisites/#a-container-capable-device).

## Device-mode button

MikroTik built it that way. Device-mode limits what a router allows, to protect it from an
attacker who gained access, so changing it takes physical access: after `/system/device-mode/update
container=yes`, someone presses the reset or mode button, or power-cycles the router, within five
minutes ([MikroTik's device-mode
page](https://help.mikrotik.com/docs/spaces/ROS/pages/93749258/Device-mode)). No tool can do it
remotely: [Device mode](https://jmrplens.github.io/mikroscope/install/prerequisites/#device-mode-containeryes).

## Router cost

At the install default of 10 Hz the agent costs 2.69 % of one core
and 13.2 MiB of memory, read from its own cgroup, and 16.83 %
at 100 Hz. That is over the project's own CPU budget of 2 % and inside its
memory budget of 16 MiB: [Agent cost](https://jmrplens.github.io/mikroscope/cost/), with how to measure
it on your router.

## Production use

The agent never connects out and presents no credential. Every write is listed before it is made
and tagged, and `uninstall` removes everything the install created and verifies that nothing is
left: a scripted round trip left the router's `/export` byte-identical
([verified](https://jmrplens.github.io/mikroscope/about/status/#verified-export-identical)). The container runs `privileged=yes`, a real
grant: [Security model](https://jmrplens.github.io/mikroscope/security/).

## Interface traffic

Not from inside the container. `/proc/net/dev` and the other network files are per network
namespace, so there they count the container's own veth, and `privileged=yes` does not change
that. Per-interface bytes and packets come from the RouterOS API, which the collector merges on the
agent's clock:
[Container visibility](https://jmrplens.github.io/mikroscope/limits/namespaces/#the-network-is-the-containers-own).

## cpu-load window

About one second. RouterOS `cpu-load` tracks a trailing mean of about a second of the kernel's busy
time, reaches the API a fraction of a second late, and is not a sixty-second average
([measured](https://jmrplens.github.io/mikroscope/about/status/#campaign-cpu-load-window-2026-09-15)). A burst shorter than that second
is averaged into it: [RouterOS API
tier](https://jmrplens.github.io/mikroscope/sinks/api-tier/#how-many-seconds-does-routeros-cpu-load-average-over).

## SNMP and mktxp

mikroscope does not replace SNMP or mktxp. It does not replace the RouterOS API either, and takes
per-interface traffic from it. What it adds is the kernel's own view, which none of the others is
documented to read: per-core ticks at up to 100 Hz, softirqs, softnet drops and squeezes, and the
kernel log. Where no container runs, SNMP or mktxp is the tool:
[Compared with alternatives](https://jmrplens.github.io/mikroscope/start/compared/).

## Grafana dashboards

`install` does not set up Grafana: it writes only to the router. The collector does, when it runs
with `--grafana <url>` and a Grafana service-account token in `GRAFANA_TOKEN`: at every start it
creates or corrects the datasource and publishes the dashboard of each store it can describe:
InfluxDB, Elasticsearch and PostgreSQL (through `--postgres`) on their own, Prometheus and Graphite
once given the address in `--grafana-datasource-url`.
`mikroscope dashboards publish`, given the collector's sink flags and `--grafana`, does the same
once without collecting, and `dashboards import` or Grafana's own import binds a dashboard to a
datasource you already have: [Set up in Grafana](https://jmrplens.github.io/mikroscope/dashboards/import-and-check/).

## Outbound connections

The agent sends nothing off the router. It serves HTTP on its veth address and makes no outbound
connection, and there is no update check. Your collector pulls from it, and every sink token and
API credential stays on your host, because whatever sits in the container's envlist is treated as
readable by every RouterOS user with `read`: [Security model](https://jmrplens.github.io/mikroscope/security/).

## See also

- [Compared with alternatives](https://jmrplens.github.io/mikroscope/start/compared/): SNMP, The Dude, Graphing, the
  Profiler, mktxp and mikrotik-exporter, cell by cell.
- [Glossary](https://jmrplens.github.io/mikroscope/reference/glossary/): envlist, veth, PMU, PSI, softnet and the other terms
  these answers use.
- [Tested on](https://jmrplens.github.io/mikroscope/about/status/): the devices, versions and results behind every answer.
