A website was visited from my network. How do I find device and SSID info?

The1Metallian
Here to help

A website was visited from my network. How do I find device and SSID info?

I got an email from my VeloCloud (SDWAN appliance) alerting me of high circuit utilization. One of the top 5 websites being visited was a gaming site.

 

How can I search on the Meraki dashboard if the website was indeed visited through our Wi-Fi (because it could have been through the wired connection), and if it was, device, AP and SSID info?

 

Thanks! 

11 Replies 11
alemabrahao
Kind of a big deal

You can check it on Network-wide > Clients page or Traffic Analytics.

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Traffic_Analysis_and_Classification

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
The1Metallian
Here to help


@alemabrahao wrote:

You can check it on Network-wide > Clients page or Traffic Analytics.

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Traffic_Analysis_and_Classification


Thanks for the prompt trply.

 

If I search on Clients page, i can't search for a domain. I can list applications, some will say the name, like "Facebook" or "Gmail", but not all wesbites are there. And if I look at Traffic Analytics, I get a list that I can sort by destination, but there are only 110 entries for an entire week for all SSIDs, and it's gotta be wrong. We are a public building and had over 15,000 people in the building this past weekend alone. Only 110 lines for a whole week?  

alemabrahao
Kind of a big deal

Unfortunately you will not be able to filter a specific website or domain.

The best way would be if you have a firewall then you can compare the firewall logs which usually tell you the website and associate it with the client and then compare them with the MR client logs.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Mloraditch
Kind of a big deal

Meraki reporting is not great for your specific need. While it's possible you could find what you are looking for, I would not bet on it (and it sounds like you haven't).  Especially as it sounds like you may only have Meraki Wireless. Do you have MS and MXs or ? In theory in a full Meraki environment with content filtering enabled where you were offloading logs to some sort of Syslog you might be able to track it down but if you didn't enable any sort of log/netflow offloading ahead of time you are going to be limited in your options.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
The1Metallian
Here to help


@Mloraditch wrote:

Meraki reporting is not great for your specific need.


You can say that again! It seems to me that it should be quite easy and basic.

 


@Mloraditch wrote:

Do you have MS and MXs or ? In theory in a full Meraki environment with content filtering enabled where you were offloading logs to some sort of Syslog you might be able to track it down but if you didn't enable any sort of log/netflow offloading ahead of time you are going to be limited in your options.


I don't have Meraki anything other than wireless. I have a now older Cisco ASA. It does offload logs to a Syslog, but it's only keeping a day's worth of logs fue to storage space. And honestly, the times that I searched those logs, I found them to be a PITA. I want to believe that there is something better out there. Not that it mater now. 

PhilipDAth
Kind of a big deal
Kind of a big deal

If it is high usage "now", look at the top applications used in the last 2 hours.

The1Metallian
Here to help


@PhilipDAth wrote:

If it is high usage "now", look at the top applications used in the last 2 hours.


I find good info there, but not what I asked. I can go to Network-wide, Clients, click on Application Details under the pie chart, and I see "applciations", not websites. I can click on an application, say "Miscellaneous secure web", I can see clients contributing and hosts contributing, but nothing linking client to host.

 

Moreover, under the pie chart and graph there is the list of hosts. I can sort by Usage, click on a device, and see connection history but not what sties have been visited.

alemabrahao
Kind of a big deal

Meraki won't give you the level of granularity you want.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
The1Metallian
Here to help


@alemabrahao wrote:

Meraki won't give you the level of granularity you want.


Clearly! But I think it should 

 

Gopinath_Pigili
Here to help

1.Log in to your Meraki Dashboard.

 

2.Go to Network-wide > Clients.

Use the search bar to enter the website domain (e.g., facebook.com) — this can help you identify which client accessed it.

You can also filter by time to narrow down to when the access occurred.

 

3.Inspect Client Details

Click the Client name or MAC address.

Review:

SSID they were connected to: Device type, IP address,Hostname, Usage and traffic details, including visited web domains

 

4. Use Event Logs

Go to Network-wide > Event log.

Filter by Client MAC or type of event (e.g., "Content filtering block" or "DNS request").

This can help validate web access history.

 

Thanks

The1Metallian
Here to help


@Gopinath_Pigili wrote:

1.Log in to your Meraki Dashboard.

 

2.Go to Network-wide > Clients.

Use the search bar to enter the website domain (e.g., facebook.com) — this can help you identify which client accessed it.

You can also filter by time to narrow down to when the access occurred.

 

3.Inspect Client Details

Click the Client name or MAC address.

Review:

SSID they were connected to: Device type, IP address,Hostname, Usage and traffic details, including visited web domains

 

4. Use Event Logs

Go to Network-wide > Event log.

Filter by Client MAC or type of event (e.g., "Content filtering block" or "DNS request").

This can help validate web access history.

 

Thanks


This doesn't work. Once I have the list of clients, I type a couple of websites in the search bar that I know were visited and I get a "no matches found"

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.