Cisco Meraki MX Integration with SIEM

Solved
BS
Getting noticed

Cisco Meraki MX Integration with SIEM

Hi All,

 

I'm looking for some documentation or your inputs on SIEM integration with Meraki MX products.

Is there any specific requirements? is it possible ?  anyone using it?

 

Regards

BS

 

1 Accepted Solution
NolanHerring
Kind of a big deal

Well not many options to choose from, but I just figured the wireless event log for example is probably not relevant to what he is looking for.  😃

 

Untitled.jpg

Nolan Herring | nolanwifi.com
TwitterLinkedIn

View solution in original post

7 Replies 7
NolanHerring
Kind of a big deal

The only thing I know of is using syslog for security/IDS events to a 3rd party SIEM collector.
Nolan Herring | nolanwifi.com
TwitterLinkedIn
BS
Getting noticed

Thanks Nolan

Is it just pointing to the SIEM IP address?
NolanHerring
Kind of a big deal

Far as I know yes, just the IP address via syslog option. Just filter the syslog to only send IDS
Nolan Herring | nolanwifi.com
TwitterLinkedIn
jdsilva
Kind of a big deal

IMO I wouldn't filter the Syslog form the MX. All that flow data can be ingested by a SIEM as well. If it was me I'd send everything available. 

NolanHerring
Kind of a big deal

Well not many options to choose from, but I just figured the wireless event log for example is probably not relevant to what he is looking for.  😃

 

Untitled.jpg

Nolan Herring | nolanwifi.com
TwitterLinkedIn
jdsilva
Kind of a big deal

@NolanHerring Wireless logs aren't available from an MX. You must be looking at a combined network 🙂

NolanHerring
Kind of a big deal

Oh I am. Good point 😃
Nolan Herring | nolanwifi.com
TwitterLinkedIn
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels