RADIUS Logs are often important to debugging an authentication issue, so I would recommend collecting those as well. With RADIUS Accounting you can get IP address as well.
You might also want to look into Webhooks for the Alerts notifications. These are important, and not always in the syslog, and most customers use email to send alerts, but using Webhooks let's you log them!
Why are webhooks and syslog different?! It seems odd at first I know. Webhooks are alerts from the Meraki Cloud "controller" while syslog is the hardware device sending it's logs, so they are two different sources. Syslog is not "secure" and therefore only offered over your internal network, not to a public IP address. Can you get them all from one source? Yes, technically you can get syslog from the Cloud as well, but it's not a stream it's an API REST call you would have to poll every X minutes.
The Meraki Syslog is easy and reliable. Check out the documentation:
https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Syslog_Server_Over...https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Meraki_Device_Repo...https://documentation.meraki.com/zGeneral_Administration/Cross-Platform_Content/Alerts_and_Notificat...https://documentation.meraki.com/zGeneral_Administration/Other_Topics/Webhooks
Colin Lowenberg
wireless engineer and startup founder, formerly known as "the API guy", now I run a
Furapi, the therapy dog service, and
Lowenberg Labs, an IT consulting company.