All Apps and Add-ons

Trying to understand Meraki data

noam
New Member

Hello everyone,

We've recently installed the Add On for Cisco Meraki and have configured Splunk as the syslog server.

I have been trying to explore failure and error events but I cant seem to fully understand what I am seeing.

I also havent been able to find any worthy reference online.

For instance,  looking at eventData.reason, I dont know what these values represent.

Does anyone have a clue or any successful experience with integrating Splunk for Meraki?

noam_0-1698562038134.png

 

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It seems like you've successfully integrated Meraki with Splunk.  Interpreting the data is another matter and probably calls for Meraki documentation (perhaps this will get you started https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Meraki_Event_Log).

FTR, Splunk recommends NOT using a Splunk instance as a syslog server as data will be lost when the instance restarts.  Splunk recommends using a dedicated syslog server such as syslog-ng, rsyslog, or Splunk Connect for Syslog.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...