本文にスキップ

Cisco Meraki MX Integration

Overview

Cisco Meraki MX appliances provide cloud-managed security and SD-WAN. KYRA MDR collects Meraki syslog data for security event monitoring and threat detection. This integration requires a Meraki Enterprise or Advanced Security license.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Cisco Meraki Dashboard administrative access
  • Meraki MX appliance with Enterprise or Advanced Security license
  • Network connectivity from the MX to the collector on port 514

Configuration

Configure syslog in the Meraki Dashboard:

  1. Log in to the Meraki Dashboard
  2. Navigate to Network-wide > General > Reporting
  3. Under Syslog servers, click Add a syslog server
  4. Configure:
SettingValue
Server IPYour KYRA Collector IP
Port514
RolesSecurity events, Flows, IDS Alerts, URLs
  1. Click Save Changes

  2. Click Save Changes

Note: Changes apply automatically; no commit needed.

Verify via Meraki Dashboard API

You can use the Meraki API to verify your organization and network configuration:

Terminal window
# List organizations
curl -s -H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \
"https://api.meraki.com/api/v1/organizations" | jq .
# List networks in an organization
curl -s -H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \
"https://api.meraki.com/api/v1/organizations/{orgId}/networks" | jq .
# Get syslog servers configured for a network
curl -s -H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \
"https://api.meraki.com/api/v1/networks/{networkId}/syslogServers" | jq .
# Update syslog servers via API
curl -s -X PUT \
-H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"servers": [
{
"host": "<COLLECTOR_IP>",
"port": 514,
"roles": ["Security events", "Flows", "IDS alerts", "URLs"]
}
]
}' \
"https://api.meraki.com/api/v1/networks/{networkId}/syslogServers"

Verify Log Reception

Terminal window
# On the KYRA Collector, verify incoming syslog from Meraki
sudo tcpdump -i any port 514 -A | grep meraki
# Check rsyslog for Meraki events
tail -f /var/log/syslog | grep -i meraki

Collected Log Types

Log TypeDescriptionSecurity Use
Security EventsMalware, IDS alertsThreat detection and response
FlowsNetwork connection logsTraffic analysis, anomaly detection
URLsWeb browsing activityContent filtering, phishing detection
IDS AlertsIntrusion detection eventsAttack detection
Air MarshalWireless security eventsRogue AP detection
IP FlowLayer 3 flow informationNetwork forensics

Troubleshooting

No logs arriving: Meraki requires outbound access to the syslog server. Ensure no upstream firewall blocks the connection from the MX appliance.

Missing security events: Verify the Meraki license includes Advanced Security features. Some log types require specific license tiers.

Intermittent logs: Meraki syslog uses UDP by default. Consider using a local relay to convert UDP to TCP for reliable delivery.

Contact kyra@seekerslab.com for support.