@sungod's answer is the best one IMO for what you are describing due to the real-time detailed analytics that it provides, pending that you have a Netflow collector to analyze the flows. Alternatively, since you mention the likes of Kibana (and/or if using the ELK stack) you can export syslog to obtain flow logs. However, it will not be as detailed as Netflow. https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Event_Types_and_Log_Samples#Meraki_MX_Security_Appliance
... View more