All Apps and Add-ons

Why are there no Traffic logs from Splunk Add-on for Cisco Meraki?

gordo32
Communicator

Recently deployed this add-on, but it doesn't seem to bring back Traffic or URL logs like we did when using the TA-meraki & syslog.

Are these not supported with the API-based mechanism, or is there something I'm missing - like a setting on the Meraki end to include these logs?

Thanks,

Gord T.

Labels (1)
0 Karma

gordo32
Communicator

A little more investigation on this, and there appears to be inconsistent information in the Meraki documentation on this. The top row of the table in this document states in the "device flow" information is available via API, but this document list URLs & Flows as Syslog messages, and documents Event Log separately (and I believe ONLY eventlog details are sent to Meraki Cloud).

Can anyone confirm whether Flows and/or URL events are eventually planned? For now, it looks like syslog is my best choice.

0 Karma

jgeremia
New Member

wanted to chime in and say this is my experience as well. One thing I was going to do for this was set up Splunk connect for syslog and push those logs to it. Splunk Connect for Syslog

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...