All Apps and Add-ons

Trying to understand Meraki data

noam
New Member

Hello everyone,

We've recently installed the Add On for Cisco Meraki and have configured Splunk as the syslog server.

I have been trying to explore failure and error events but I cant seem to fully understand what I am seeing.

I also havent been able to find any worthy reference online.

For instance,  looking at eventData.reason, I dont know what these values represent.

Does anyone have a clue or any successful experience with integrating Splunk for Meraki?

noam_0-1698562038134.png

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It seems like you've successfully integrated Meraki with Splunk.  Interpreting the data is another matter and probably calls for Meraki documentation (perhaps this will get you started https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Meraki_Event_Log).

FTR, Splunk recommends NOT using a Splunk instance as a syslog server as data will be lost when the instance restarts.  Splunk recommends using a dedicated syslog server such as syslog-ng, rsyslog, or Splunk Connect for Syslog.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...