Cisco Meraki MX Integration
Overview
Cisco Meraki MX appliances provide cloud-managed security and SD-WAN. KYRA MDR collects Meraki syslog data for security event monitoring and threat detection. This integration requires a Meraki Enterprise or Advanced Security license.
Prerequisites
- A KYRA MDR Collector installed and running
- Cisco Meraki Dashboard administrative access
- Meraki MX appliance with Enterprise or Advanced Security license
- Network connectivity from the MX to the collector on port 514
Configuration
Configure syslog in the Meraki Dashboard:
- Log in to the Meraki Dashboard
- Navigate to Network-wide > General > Reporting
- Under Syslog servers, click Add a syslog server
- Configure:
| Setting | Value |
|---|---|
| Server IP | Your KYRA Collector IP |
| Port | 514 |
| Roles | Security events, Flows, IDS Alerts, URLs |
-
Click Save Changes
-
Click Save Changes
Note: Changes apply automatically; no commit needed.
Verify via Meraki Dashboard API
You can use the Meraki API to verify your organization and network configuration:
# List organizationscurl -s -H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \ "https://api.meraki.com/api/v1/organizations" | jq .
# List networks in an organizationcurl -s -H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \ "https://api.meraki.com/api/v1/organizations/{orgId}/networks" | jq .
# Get syslog servers configured for a networkcurl -s -H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \ "https://api.meraki.com/api/v1/networks/{networkId}/syslogServers" | jq .
# Update syslog servers via APIcurl -s -X PUT \ -H "X-Cisco-Meraki-API-Key: YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "servers": [ { "host": "<COLLECTOR_IP>", "port": 514, "roles": ["Security events", "Flows", "IDS alerts", "URLs"] } ] }' \ "https://api.meraki.com/api/v1/networks/{networkId}/syslogServers"Verify Log Reception
# On the KYRA Collector, verify incoming syslog from Merakisudo tcpdump -i any port 514 -A | grep meraki
# Check rsyslog for Meraki eventstail -f /var/log/syslog | grep -i merakiCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Security Events | Malware, IDS alerts | Threat detection and response |
| Flows | Network connection logs | Traffic analysis, anomaly detection |
| URLs | Web browsing activity | Content filtering, phishing detection |
| IDS Alerts | Intrusion detection events | Attack detection |
| Air Marshal | Wireless security events | Rogue AP detection |
| IP Flow | Layer 3 flow information | Network forensics |
Troubleshooting
No logs arriving: Meraki requires outbound access to the syslog server. Ensure no upstream firewall blocks the connection from the MX appliance.
Missing security events: Verify the Meraki license includes Advanced Security features. Some log types require specific license tiers.
Intermittent logs: Meraki syslog uses UDP by default. Consider using a local relay to convert UDP to TCP for reliable delivery.
Contact kyra@seekerslab.com for support.