All Apps and Add-ons

Why are there no Traffic logs from Splunk Add-on for Cisco Meraki?

gordo32
Communicator

Recently deployed this add-on, but it doesn't seem to bring back Traffic or URL logs like we did when using the TA-meraki & syslog.

Are these not supported with the API-based mechanism, or is there something I'm missing - like a setting on the Meraki end to include these logs?

Thanks,

Gord T.

Labels (1)
0 Karma

gordo32
Communicator

A little more investigation on this, and there appears to be inconsistent information in the Meraki documentation on this. The top row of the table in this document states in the "device flow" information is available via API, but this document list URLs & Flows as Syslog messages, and documents Event Log separately (and I believe ONLY eventlog details are sent to Meraki Cloud).

Can anyone confirm whether Flows and/or URL events are eventually planned? For now, it looks like syslog is my best choice.

0 Karma

jgeremia
New Member

wanted to chime in and say this is my experience as well. One thing I was going to do for this was set up Splunk connect for syslog and push those logs to it. Splunk Connect for Syslog

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...