{"repo":"H2FSpawn/wazuh-mikrotik-decoder","free":true,"listed":false,"github":"https://github.com/H2FSpawn/wazuh-mikrotik-decoder","clone":"git clone https://github.com/H2FSpawn/wazuh-mikrotik-decoder.git","description":"Wazuh decoders and detection rules for MikroTik RouterOS syslog output. Covers firewall drops, DHCP leases, system events, login failures, and brute force detection. Tested on RouterOS 7.x and Wazuh 4.12–4.14.","language":null,"stars":16,"topics":["decoder","homelab","mikrotik","router-os","routeros","siem","syslog","wazuh","wazuh-integration"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"wazuh-mikrotik-decoder Wazuh decoders and detection rules for MikroTik RouterOS syslog output. RouterOS uses a syslog format that Wazuh's built-in parsers don't understand. Firewall drops, DHCP leases, system events — all of it lands as unstructured noise unless you have a decoder that knows what to look for. This is that decoder. What it covers Three syslog topics, with structured field extraction: - Firewall — source IP, source port, destination IP, and destination port; drop detection (rules 110001–110002) - DHCP — assigned lease events with IP, MAC address, and client hostname (rule 110003); other DHCP events (offering, deassigned) match without field extraction - System — general RouterOS system messages, login failure detection, brute force detection, interface down events (rules 110004–110007) Tested on RouterOS 7.x and Wazuh 4.12–4.14. Installation Wazuh manager: Add a syslog listener to /var/ossec/etc/ossec.conf if you don't have one: Restrict allowed-ips to your own network. UDP 514 should never be reachable from the internet. MikroTik: See docs/mikrotik-syslog-setup.md for the full RouterOS configuration. Testing Sample log lines for all supported event types are provided in test-logs/test-logs.txt . Use them with wazuh-logtest to verify the decoder and rules are working correctly: Paste one line at a time and check Phase 2 for the expected decoded fields. Known limitations Firewall: TCP flag annotations prevent field extraction RouterOS can append TCP flags like (","default_branch":null,"files":null,"tree":[],"storefront":"/r/H2FSpawn","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/H2FSpawn/wazuh-mikrotik-decoder/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}