- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've successfully installed and configured the TA-meraki app and have all the CIM compliant data coming into Splunk, my question is...why am I not getting all the logs in Splunk that appear in the Meraki Dashboard?
I'm currently receiving events for the following apps/roles in Splunk (below on the right), but when comparing it to the Roles configured on the Meraki-side (to the left), we're not receiving anything from the Security Events Role in Splunk, although it's logging fine into the Meraki dashboard. Any help would be GREATLY appreciated!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki responded to us stating that not all Meraki logs are designed to be ingested by syslog when you configure the syslog option. So basically, it's expected to see logs in the Meraki dashboard you're not finding in Splunk.
Sorry, I'm sure it's not the answer you were looking for. Hopefully Meraki updates this moving forward!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hello did you get to the bottom of this ? we have the same issue
Thanks
Dave
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki responded to us stating that not all Meraki logs are designed to be ingested by syslog when you configure the syslog option. So basically, it's expected to see logs in the Meraki dashboard you're not finding in Splunk.
Sorry, I'm sure it's not the answer you were looking for. Hopefully Meraki updates this moving forward!
