Getting Data In

TA-meraki Not Logging all Events to Splunk

astackpole
Path Finder

I've successfully installed and configured the TA-meraki app and have all the CIM compliant data coming into Splunk, my question is...why am I not getting all the logs in Splunk that appear in the Meraki Dashboard?

I'm currently receiving events for the following apps/roles in Splunk (below on the right), but when comparing it to the Roles configured on the Meraki-side (to the left), we're not receiving anything from the Security Events Role in Splunk, although it's logging fine into the Meraki dashboard. Any help would be GREATLY appreciated!

meraki-roles.pngScreen Shot 2020-11-16 at 1.40.17 PM.png

 

Labels (1)
0 Karma
1 Solution

astackpole
Path Finder

Meraki responded to us stating that not all Meraki logs are designed to be ingested by syslog when you configure the syslog option. So basically, it's expected to see logs in the Meraki dashboard you're not finding in Splunk.

Sorry, I'm sure it's not the answer you were looking for. Hopefully Meraki updates this moving forward!

View solution in original post

0 Karma

davidward2829
Observer

hello did you get to the bottom of this ? we have the same issue 

Thanks 

Dave

0 Karma

astackpole
Path Finder

Meraki responded to us stating that not all Meraki logs are designed to be ingested by syslog when you configure the syslog option. So basically, it's expected to see logs in the Meraki dashboard you're not finding in Splunk.

Sorry, I'm sure it's not the answer you were looking for. Hopefully Meraki updates this moving forward!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...