Cisco Meraki (API)
You can integrate Cisco Meraki (API) with Sophos Fusion so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Cisco Meraki (API) product overview
Cisco Meraki offers a cloud-managed firewall solution that integrates with Meraki's broader suite of network products. The platform provides centralized management, visibility, and control.
What we ingest
Sophos XDR collects Cisco Meraki Dashboard API data by polling Meraki using the credentials from your integration (for example, API token, Organization ID, and optional Base URL). Ingestion is HTTPS JSON from the Meraki REST API, rather than syslog to the XDR collector.
For organization appliance security events, Sophos XDR calls Meraki’s Get Organization Appliance Security Events operation and ingests the "Security Event" records it returns for your organization over the requested time window (as defined by Meraki’s API). This includes the eventType values Meraki emits (for example, those that surface as "IDS Alert" and "File Scanned").
Meraki security events can reflect situations such as blocked malware, suspicious outbound connections, exploit-style signatures, or login abuse, depending on appliance telemetry and your policies. Here are some examples:
- Malware accessed
- Brute force login attempts
- C2 traffic
- Cryptocurrency miner outbound connections
- SQL injection attempts
See Event and data types for a more detailed summary of how data types get normalized to events.
Note
The Cisco Meraki (API) integration only sends Cisco "Security Events" logs. If you want to send others, such as "Flows" or "IDS Alerts", use the syslog-based Cisco Meraki integration. See Cisco Meraki (syslog).
Event and data types
We ingest the following event and data types from Cisco Meraki (API):
- Intrusion detection (IDS/IPS): Organization appliance security events with
eventTypeIDS Alert: Signature and rule identifiers, priority and classification, blocked flag,srcIp/destIpendpoints and protocol, and descriptive message text from the appliance. Normalized to third-party security alert telemetry. - File inspection: Organization appliance security events with
eventTypeFile Scanned: Requesteduri,fileHash,canonicalName/ threat naming,disposition,action, client identifiers, and destination context. Normalized to antivirus and file protection telemetry.
Together, these cover common reporting scenarios such as blocked malware, suspicious outbound connections, exploit-style signatures, and similar patterns, depending on what your appliances emit and your policies surface.
Data provided by this integration
Data provided by Cisco Meraki (API) gets normalized to the following schemas:
antivirusthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.