Cisco Meraki is a hardware vendor and sells cloud-controlled security appliances (firewall), switches, and access points via a centralized managed platform. This technology pack will process Cisco Meraki logs, providing normalization and enrichment of common events of interest.
Configure Cisco Meraki to transmit Syslog to your Graylog server Syslog input.
+
-
If this stream is already created then nothing will be changed. This stream will be created if it does not exist, and it will be configured to route messages to the Cisco Devices index set. There should not be any rules configured for this stream.
-
Index Set Configuration
-
This technology pack includes one index set definition:
+
Stream Configuration
+
This technology pack includes 1 stream:
-
“Cisco Devices Event Log Messages”
+
"Illuminate:Cisco Device Messages"
-
If this index set is already defined, then nothing will be changed. If this index set does not exist, then it will be created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.
Hint: If this stream does not exist prior to the activation of this pack then it will be created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.
+
This technology pack includes 1 index set definition:
-
Configure Cisco Meraki to transmit Syslog to your Graylog server Syslog input.
+
"Cisco Devices Event Log Messages"
-
-
Meraki Syslog and Nanosecond Timestamps
-
-
-
Cisco Meraki devices are sometimes configured to send epoch timestamps with nanoseconds; the Graylog syslog input cannot parse these messages and will drop them. If your device is configured to send nanosecond timestamps please configure a Raw/Plaintext UDP input for Graylog and configure the Meraki to send logs to the raw input. This input must be configured to use a different port than any other existing UDP input. The parsing of epoch timestamps will be addressed in a future version of Graylog.
-
-
-
What is Provided
+
+
+
Hint: If this index set is already defined, then nothing will be changed. If this index set does not exist, then it will be created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.
+