Splunk Dev

How to pull Meraki Syslog into Splunk in order to monitor internal port scanning?

cbcadmin
Loves-to-Learn Lots

Hey all,

I'm trying to pull in the Syslog or our Meraki MX to our on-premise Splunk Enterprise in order to monitor internal port scanning. Right now I have the Syslogs coming in via the Data input > UDP (514). I see all the data being pulled in correctly however when I search internal traffic communication it shows everything going to the broadcast IP. I'm not sure if I should be using a different method, but I would appreciate some guidance on best practices to monitor internet traffic.

Thanks!

Screen Shot 2022-07-18 at 7.16.22 AM.png

Screen Shot 2022-07-18 at 2.31.35 PM.png

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...