Cisco Meraki

The IBM® Security QRadar® Log Insights data source type for Cisco Meraki collects Syslog events from a Cisco Meraki device.

To integrate Cisco Meraki with QRadar Log Insights, complete the following steps:
  1. Configure your Cisco Meraki device to send Syslog events to QRadar Log Insights.
  2. If QRadar Log Insights does not automatically detect the data source, add a Cisco Meraki data source in QRadar Log Insights. The following table describes the parameters that require specific values to collect Syslog events from Cisco Meraki:
    Table 1. Cisco Meraki Syslog data source parameters
    Parameter Value
    Data source type Cisco Meraki
    Connector Syslog
    Data source identifier

    The IPv4 address or host name that identifies the data source.

    If your network contains multiple devices that are attached to a single management console, specify the IP address of the individual device that created the event. A unique identifier, such as an IP address, prevents event searches from identifying the management console as source for all of the events.

For more information about adding a data source in QRadar Log Insights, see Adding ingestion data sources.

If you are an IBM QRadar user, see Terminology changes for QRadar customers.