We have syslog configured in Network Wide > Configure > General > Reporting. We use a custom port and send "Security Events" however the syslog server is not receiving syslog messages on the server. I tried running a capture but do not see any traffic between the MX and the syslog server.
What would be the source ip address of Meraki syslog messages? Should I be able to view those messages in wireshark?