Hello everyone,
I wanted to ask you all about the log monitoring on the MX appliances. We have MX250's in our network and we are having a real hard time tracking down firewall/filtering situations. For example, we really need to be able to see what rules are triggering for content filtering, app blocking, layer 3 blocking, country blocking, etc. and it just seems near impossible to get this information from the Meraki Cloud Console. Many events also seem to be dropped. The console said this is due to performance limitations on the MX.
I was reading through some posts here and on other sites (reddit, etc) that the best way to accomplish this is through Syslog. I tried sending syslogs to Solarwinds and Syslog Watcher but didn't like the interface. It was still difficult to comb through. I think I may have allowed the wrong events though. The even I allowed was URLs which just gave me a list of urls being accessed by different clients but didn't tell me anything about whether they were blocked, by what policy, etc.
I was thinking of possibly using something like Graylog but I wanted to reach out to see what others are doing for this. My first question is what roles do you guys use when sending to syslog? I saw netflow there as well? Is that something that would give me what I am looking for? What software do you guys use that you like that gives you a nice ui/interface to comb through these events?
Our previous appliance was a Palo Alto which made it easy to kind of track these sort of things down. I know I am not going to be able to get back to that but I am just looking for a way to get me closer as right now every time I have troubleshoot some firewall blocking issue I feel like I am just taking pot shots in the dark trying to do pcaps and such. I appreciate your time and suggestions. Thank you.