In the context of Cisco Meraki, each individual device such as MX Security Appliances, MR Access Points, and MS switches can be configured to send syslog messages to a syslog server. These devices generate different types of logs, including system logs, traffic logs, event logs, IDS alerts, URLs, and flows. Therefore, each device would count as a separate log source.
This might give the impression of a single source, but in reality, each device is a separate source of logs.
https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Server_Overv...
Please consult with your Cisco Meraki representative for the most accurate information as it can vary based on your specific network configuration.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.