SYSLOG events from MX security appliance to QRadar SIEM

Pcozzi70
Just browsing

SYSLOG events from MX security appliance to QRadar SIEM

We are sending syslog events from our Meraki MX84 (v.MX 18.107) to QRadar Event Collector.
All the Roles for that syslog server have been enabled in Meraki dashboard.
Though we are not able to get any info on client VPN login/logout/etc.

 

Is there any method to get these info via syslog or anyway on a remote SIEM event collector?

 

Thanks in advance

 

Paolo

2 Replies 2
alemabrahao
Kind of a big deal
Kind of a big deal

The informations that you can receive via syslog are limited. Take a look at the documentation.

 

https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Meraki_Device_Repor...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Pcozzi70
Just browsing

Yes I have already seen that page.

Do you think is there any method via webhooks/API to get infos about VPN client connection/disconnection as I see on dashboard event log?

Thanks

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels