Short answer: you can use Syslog or the API to query URLs that have been accessed via your Meraki infrastructure externally.
But would that make sense? Meraki has strong built-in security backed by Talos. Any attacker that directly connects back to something ending in .ru would probably be found within seconds nonetheless.
From my point of view, you'd be better off with leveraging Content Security and Threat Filtering capabilities on your MX and keep a close eye to your Security Overview.
What you can do in addition to that would be pushing Syslog out into a SIEM platform and / or use a network anomaly detection system like Secure Network Analytics. But the possibilities here are for more efficient than simply sending out an alert for some access to a russian website.