The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About johnd3
johnd3

johnd3

Conversationalist

Member since Jul 20, 2018

‎02-26-2019
Kudos from
User Count
cwal21
cwal21
1
PhilipDAth
Kind of a big deal PhilipDAth
1
jdsilva
jdsilva
1
View All

Community Record

3
Posts
3
Kudos
0
Solutions

Badges

1st Birthday View All
Topics johnd3 has Participated In
  • Topics johnd3 has Participated In
  • Latest Contributions by johnd3

Re: Exclude certain messages/services from change log

by johnd3 in Security / SD-WAN
‎02-06-2019 01:27 PM
‎02-06-2019 01:27 PM
Had a feeling...thanks! ... View more

Wish: Include sent and received data volumes in MX flow logs

by johnd3 in Security / SD-WAN
‎09-14-2018 10:36 AM
3 Kudos
‎09-14-2018 10:36 AM
3 Kudos
We have a SIEM tool that consumes syslog from an MX appliance to aggregate/analyze traffic and track connections between internal assets and external malicious actors.   We are currently able to parse syslog messages from an MX appliance to determine: 1. the external IP/domain connected with 2. the internal IP(s), ports interacted with 3. traffic type and encryption status 4. whether the connection initiated internally or externally   It is also of vital importance to determine the volume of data transferred both in and out of a network over the connection between the source and destination. Currently, the MX flow logs do not support this. I know many other firewalls include this in their flow log equivalents, and I know there are ways to view and export this info from the MX dashboard. However, we need a passive, automated way to consume this data without implementing manual workarounds. We would like to see Meraki include this in its flow logs as it is obviously helpful in narrowing down problem points.   Said another way, the current syslog messages resemble the following: <134>1 1536610215.9836262378 XXX_XXX_X0X0 flows allow src=10.10.12.10 dst=192.218.232.24 mac=C7:E4:B3:E2:51:28 protocol=udp sport=51185 dport=1900   and we would want them to include something similar to the fields at the end of the message:   <134>1 1536610215.9836262378 XXX_XXX_X0X0 flows allow src=10.10.12.10 dst=192.218.232.24 mac=C7:E4:B3:E2:51:28 protocol=udp sport=51185 dport=1900 duration="30" sent_bytes="84" rcvd_bytes="84" ... View more
Kudos from
User Count
cwal21
cwal21
1
PhilipDAth
Kind of a big deal PhilipDAth
1
jdsilva
jdsilva
1
View All
My Top Kudoed Posts
Subject Kudos Views

Wish: Include sent and received data volumes in MX flow logs

Security / SD-WAN
3 1310
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki