MetricSplit › Guides › MikroTik

How to send NetFlow or IPFIX from a MikroTik router to a flow collector

RouterOS exports flow records with Traffic Flow, switched on for chosen interfaces and sent to one or more targets.

What it sends

NetFlow v1, v5, v9 or IPFIX, as you choose per target. With IPFIX you choose the fields, including in-interface and out-interface.

Steps

  1. Switch it on: /ip traffic-flow set enabled=yes interfaces=all (MikroTik's defaults: active-flow-timeout 30m, inactive-flow-timeout 15s, cache-entries 4k).
  2. Set the active timeout to 1 minute: /ip traffic-flow set active-flow-timeout=1m (MikroTik's documentation gives the default, 30m, and no minimum). Why: MetricSplit works in 5-minute readings, so a long-running flow has to be reported at least every minute to land in the right reading.
  3. Add the collector, using IPFIX: /ip traffic-flow target add dst-address=192.0.2.10 port=2055 version=ipfix
  4. Make sure the IPFIX fields include src-address, dst-address, src-port, dst-port, protocol, bytes, packets, in-interface and out-interface (MikroTik lists them under the IPFIX settings).

Check it's working

A packet capture on the collector (tcpdump -ni any udp port 2055) shows whether records arrive.

Vendor documentation

What MetricSplit does with flow records

MetricSplit receives flow records (metadata only, no packet contents) and is never in your traffic path. It classifies your traffic as business, neutral or non-business, by application and by site, and gives each circuit a decision (rebalance, right-size, restrict or upgrade) with the evidence.

Book a free assessment

All vendors