Wayseer

Marketplace

BGP (RIS Live)

wayseer-labs/bgp · version 0.1.0 · published 7 October 2026 ·

Live BGP routing for watched prefixes and ASes, from RIPE RIS Live.

  1. Get it with >modules.get id=wayseer-labs/bgp: Wayseer downloads the package for your platform, checks it, shows what it declares, and installs it on Y (getting a module).
  2. Name it in your config as a source of kind: external with module: wayseer-labs/bgp, and its own options as below (configuration). A config that names it before it's installed offers to get it when Wayseer opens.

It runs under a license key that covers modules from others (pricing). Or download the package for your platform below and install it with >modules.install file= and its path (installing a package).

BGP (RIS Live) 0.1.0 packages
Linux x86-64wayseer-labs-bgp-0.1.0-linux-amd64.wsmod.tar.gz
12.1 MB
SHA-256 85363c7c750d613ea9e961fcb62e9b1668ba8d03cc29bdf0785f42d65b87a9ee
Linux ARM64wayseer-labs-bgp-0.1.0-linux-arm64.wsmod.tar.gz
11.1 MB
SHA-256 05657a23ca31133ec545f3d896501559487951bd501d25ea617ec69eab434a8d
Windows x86-64wayseer-labs-bgp-0.1.0-windows-amd64.wsmod.zip
12.1 MB
SHA-256 6dd9a116204818e7b3132af765cd759778d7ef78604b84ad9a69890eadf2ee8d
macOSNot offered yet.

What it may do

What its signed manifest declares. The app holds it to this: it may report only these kinds, and offers only these actions, each waiting for you to confirm it.

Reports
ASes bgp/as, Prefixes bgp/prefix, Peers bgp/peer, Collectors bgp/collector
Actions
None: it only reads
Reaches
ris-live.ripe.net:443
Secrets
None
Source
github.com/wayseer-net/desktop-module-bgp at v0.1.0, commit 7f5037da034d, MIT

Using it

From the module's own documentation at v0.1.0, written by its publisher.

An external module for Wayseer Desktop that shows live BGP routing from RIPE RIS Live. You name the prefixes and origin ASes to watch. The module then shows who announces them, through which AS paths, which peers and collectors see them, and how their routes change. It raises events for possible hijacks, origin changes, new more-specifics, withdrawals and path changes.

It is not built into the app. It runs as its own program from a signed package, as wayseer-labs/bgp in the namespace bgp. Like every Wayseer module it is a lens, not a store. It keeps only a bounded working set in memory and forgets what it no longer sees.

Configuration

modules:
  - kind: external
    name: bgp
    options:
      module: wayseer-labs/bgp
      options:
        prefixes: [193.0.0.0/21, 2001:67c:2e8::/48]
        expect: {193.0.0.0/21: [3333], 2001:67c:2e8::/48: [3333]}
        hosts: [rrc00, rrc21]

url

RIS Live. Use wss:// or ws:// for WebSocket, or https://ris-live.ripe.net/v1/stream/?format=json for its HTTP stream.

Default
wss://ris-live.ripe.net/v1/ws/

client

The client identifier sent to RIS Live as ?client=, as RIPE asks. Name your organization.

Default
wayseer-bgp

prefixes

Prefixes to watch, at most 100. They must be at least /8 (IPv4) or /16 (IPv6) while more_specific is on.

more_specific

Also watch prefixes inside them.

Default
true

less_specific

Also watch prefixes that contain them.

Default
false

origins

ASNs whose every announcement is watched, at most 32.

expect

The legitimate origin ASNs of a watched prefix. Any other origin of it, or of a more-specific, is a possible hijack.

hosts

Collectors to read, such as rrc00.

Default
all

peers

Peer addresses to read.

Default
all

types

The message types to read.

Default
[UPDATE, RIS_PEER_STATE]

interval

How often changes and series points are sent, from 1s to 1m.

Default
5s

stale_after

How long something no route uses is kept unseen.

Default
1h

max_ases

The most ASes kept. The least recently seen go first.

Default
2000

max_links

The most AS adjacencies kept.

Default
5000

max_prefixes

The most prefixes kept. Watched prefixes are always kept.

Default
200

At least one of prefixes or origins is required, and types must include UPDATE. Each host and peer you name multiplies the subscriptions, and a config that needs more than 64 is refused. RIS Live is never asked for its unfiltered stream.

What it shows

bgp/prefix

A watched prefix, a more- or less-specific of one, or a prefix a watched origin announced.

Native ID
193.0.0.0/21

bgp/as

An AS seen in the path of a watched route, or as a peer's AS.

Native ID
AS3333

bgp/peer

A RIS peer, at its collector.

Native ID
192.0.2.1@rrc00

bgp/collector

A RIS route collector.

Native ID
rrc00

Edges. An AS talks_to the next AS toward the origin in a path, so the arrows follow traffic toward the prefix. The origin AS owns the prefix it announces, and a peer's AS owns the peer. A peer is a member_of its collector. A watched prefix is the parent_of its more-specifics, and a less-specific is the parent_of the watched prefix.

Status of a prefix. The status is crit when an origin isn't one expect names. It is down once every peer seen carrying the prefix has withdrawn it, and warn when more than one AS originates it. It is unknown until an announcement is seen. RIS Live streams only changes, so the module starts empty and learns routes as peers announce them. A route that is never re-announced is still kept until it is withdrawn.

Series, one point per interval:

MetricUnitKinds
bgp.announcementsper secondprefix, peer, collector
bgp.withdrawalsper secondprefix, peer, collector
bgp.path_changesper secondprefix
bgp.peerscountprefix (peers seen carrying it)

Events:

origin

Possible hijack: an origin not in expect announces the prefix or a more-specific.

Severity
critical

origin

Without expect, the prefix gets an origin it didn't have.

Severity
warn

more-specific

A more-specific of a watched prefix is announced for the first time.

Severity
warn

withdrawal

A watched prefix was withdrawn: error when no peer seen carries it any more, info otherwise. There is at most one per interval.

Severity
error / info

path-change

A peer's AS path to a watched prefix changed. There is at most one per interval.

Severity
info

peer-state

A known peer's BGP session went down, which drops its routes, or came back up.

Severity
warn / info

Bounds. Watched prefixes are always kept. Other prefixes, ASes, adjacencies, peers (1000) and collectors (64) are capped, and the least recently seen go first. Whatever no current route uses is forgotten after stale_after. At most 500 events are kept between sends, and the rest are counted in one dropped event. Each series keeps 360 points.

Connection. The module reconnects after a dropped stream. It waits 1s, then twice as long each time, up to a minute, and starts again from 1s once a stream has lasted a minute. A ris_error from RIS Live shows as the module's error, and a message it can't read shows as a note. The WebSocket connects directly. The HTTP stream honours HTTPS_PROXY.

Data source and attribution

The data comes from the RIPE NCC's Routing Information Service (RIS), at <https://www.ripe.net/ris>, through RIS Live. Its use falls under the RIPE NCC's terms of service for the website and its publicly available services. Commercial use is allowed under the RIPE NCC's RIS commercial use rules, which ask for the RIPE NCC logo, a link to <https://www.ripe.net/ris>, and this description:

The RIPE Routing Information Service (RIS) is a RIPE NCC service. With the help of network operators all over the world, RIS employs a globally distributed set of Remote Route Collectors (RRCs), typically located at Internet Exchange Points, to collect and store Internet routing data. Volunteers peer with the RRCs using the BGP protocol and RIS stores the update and withdraw messages. RIS data can be accessed via: - RIPEstat, the "one-stop shop" for all available information about Internet number resources. RIPEstat uses individual widgets to display routing and other information; - RIS Live, a real time BGP streaming API allowing server-side filtering of BGP messages by prefix or autonomous system; - RIS Raw Data, available for each route collector, with state dumps and batches of updates made available periodically; - RISwhois, that searches the latest RIS data for details of an IP address using a plaintext "whois"-style interface. It is useful when querying RIS data using scripts.

RIS Live needs no account. Set client to name yourself, and keep your filters narrow. RIPE closes connections that can't keep up.

Its data

Data from the RIPE NCC's Routing Information Service (RIS).

The RIPE Routing Information Service (RIS) is a RIPE NCC service. With the help of network operators all over the world, RIS employs a globally distributed set of Remote Route Collectors (RRCs), typically located at Internet Exchange Points, to collect and store Internet routing data. Volunteers peer with the RRCs using the BGP protocol and RIS stores the update and withdraw messages. RIS data can be accessed via: - RIPEstat, the "one-stop shop" for all available information about Internet number resources. RIPEstat uses individual widgets to display routing and other information; - RIS Live, a real time BGP streaming API allowing server-side filtering of BGP messages by prefix or autonomous system; - RIS Raw Data, available for each route collector, with state dumps and batches of updates made available periodically; - RISwhois, that searches the latest RIS data for details of an IP address using a plaintext "whois"-style interface. It is useful when querying RIS data using scripts.