Forum Discussion
David Caddick
Mar 16, 2020Iron Contributor
Sentinel & Cisco Meraki?
Has anyone had any experience with getting Cisco Meraki feeds ingesting into Sentinel?
Just checking for any gotcha's...
- GaryBusheyBronze Contributor
David Caddick I had to do it for a customer and it worked just fine using the Syslog server.
- mperrottaBrass ContributorWe are also working on this, but are running into an issue where some of the logs are getting chopped by the syslog server. It appears to be an issue only with vpn flow traffic on the MX firewall.
We have a case open trying to figure it out. - Rod_TrentMicrosoft
GaryBushey Agreed.
The instructions here (https://techcommunity.microsoft.com/t5/azure-sentinel/azure-sentinel-syslog-cef-logstash-and-other-3rd-party/ba-p/803891) work pretty well. Search that page for 'Meraki'
- Dev_ChoudharyBrass Contributor
Hi GaryBushey
can you please confirm the sentinel table in which you are getting Meraki events. It is like custom log or coming under syslog ?
- mperrottaBrass ContributorThey will show up under syslog.