Basically I am looking for a Splunk-like tool for Meraki events across 20+ networks and MX devices, 60+ switches. Given I have next to zero money aka budget (that I know of, haha), and next to zero time to maintain that tool (wearing lots of other hats) - the focus is on the simplicity, ease of maintenance. (Splunk is a bear to maintain - and can get expensive fast.) Need something simple yet where an SQL-like query would give me a fast answer to "top 10 networks with most site-to-site auto-VPN failures" and then chart the results over e.g. 3 years. If you have a suggestion, please include a screenshot (or a link) to a dashboard or report (or other KO) example of how this tool actually works, what results it produces. Context: Given Meraki's focus on ease of use and putting everything in the cloud, I was surprised to find out just how limited event search in Meraki is. Can't search for specific strings or regex in the events. Can't search across 2+ networks. Can't even export a full CSV of a specific log, or all logs. (Seriously?) Forget any sort of analytics other than what Meraki dashboards already provide. Given the (event) data is already in Meraki cloud (even if with very limited retention), I thought maybe there are good integrations with other cloud-based analytics and o11y tools - Splunk, Azure Log Analytics, Datadog, New Relic - that use the data in place... Authorize, connect, and Bob's your uncle? But... no: there's not a single one letting me search the existing data in place - must forward first to a different tool with its own storage. Hmmm, OK. There are some integrations like Cisco Meraki connector for Microsoft Sentinel - yet that is anything but simple: set up a syslog server, Sentinel agent, all that - apparently with a number of seemingly critical issues that (a) make the solution anything but simple and seem to be a recipe for a mountain of technical debt, and (b) require a purchase of another product we don't have (Sentinel) and not sure we need. there're Splunk Web Add-on for Cisco Meraki, and Splunk Add-on for Cisco Meraki, both with very sparse information - e.g. no examples of KOs, reports, dashboards - and I am hesitant to spend weeks or months on setting up a POC, only to find out there're insurmountable limitations. P.S. Please help me with the subject / title of this thread. What should it be if I am looking for a substantial upgrade to Meraki's current event retention, querying and analysis functionality? "Log aggregation" doesn't quite sound right. SIEM? This isn't about security - more about o11y and analytics that's not limited to security. Thanks!
... View more