Hello everyone,
We've recently installed the Add On for Cisco Meraki and have configured Splunk as the syslog server.
I have been trying to explore failure and error events but I cant seem to fully understand what I am seeing.
I also havent been able to find any worthy reference online.
For instance, looking at eventData.reason, I dont know what these values represent.
Does anyone have a clue or any successful experience with integrating Splunk for Meraki?
It seems like you've successfully integrated Meraki with Splunk. Interpreting the data is another matter and probably calls for Meraki documentation (perhaps this will get you started https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Meraki_Event_Log).
FTR, Splunk recommends NOT using a Splunk instance as a syslog server as data will be lost when the instance restarts. Splunk recommends using a dedicated syslog server such as syslog-ng, rsyslog, or Splunk Connect for Syslog.