Syslog Integrations

IT_Magician
Building a reputation

Syslog Integrations

Hey Meraki Community,

 

Does anyone know how to get the IDS/AMP events inside the security center show up on with Syslog integrations? For whatever reason we are not seeing these events in our SYSLOG integration, or under event viewer. You would think this information would be part of the Syslog integration and also show up in the event logs but we are not seeing it in either section.

2 REPLIES 2
Inderdeep
Kind of a big deal
Kind of a big deal

@IT_Magician : Check the below link, did you enable ids events ?

https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Meraki_Device_Repor... 

Regards/Inder
Cisco IT Blogs awarded in 2020 & 2021
www.thenetworkdna.com
IT_Magician
Building a reputation

Yes we did, based on documentation Meraki should be sending over IDS/AMP events. We have some, but the security team is saying they are getting everything except that. I am going to explore with them if the issue is on their side and report back.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels