Getting Data In

Data collection stops after initial API pull for Cisco Meraki Add-on for Splunk

Chris_Urman
Engager

I am experiencing an issue with the "Cisco Meraki Add-on for Splunk" where it connects to "api.meraki.com" grabs 5-10K events sometimes more or less then stops. The Heavy Forwarder is supposed to connect to the API five times a second but stops after only one connection. If I toggle the input off then on it will grab more data then stop again. 

I have confirmed we are not exceeding "max_content_length" and there are no errors in the internal logs. I have cases open with Splunk and Cisco. Diags are not showing anything obvious.

Has anyone else experienced this issue with the Cisco Meraki Add-On for Splunk?

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Chris_Urman 

5 times a second seems *very* frequent. The API might be limited by the amount of events returned each time, I would suggest trying to set a longer frequency and see if subsequent API calls happen succesfully.

If its trying to load historic data then it might take a little bit of time to work through and get to the current time.

Could you also check the logs and let us know what its reporting around the time the input runs?

index="_internal" source=*splunk_ta_cisco_meraki*.log*

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

Chris_Urman
Engager

Thank you for your insight. I turned the frequency down to one time per second and still the same behavior. I ran the query you provided and it returned info level events that the Splunk ingested data for the input.  No errors anywhere. 

" Events ingested in Splunk for input: cisco_meraki_airmarshal://airmarshal_SFG_Splunk, organization id: *************************, count=2264 | Total time taken: 7.438018 seconds

0 Karma

shashankD
Explorer

Try to fetch API from the recent time like from last hour, or a day.

This API comes with the limitation and if the number of events are huge in numbers then the API will fail to pull the events. try to fetch the event from recent time rather then a large interval of old data.

0 Karma

Chris_Urman
Engager

Thank you for your insights. Right now the inputs are set to a 24 hour interval. I will adjust down to one hour.

0 Karma

Chris_Urman
Engager

After adjusting the input interval the behavior is still the same. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...