Cisco Meraki (syslog)
You can integrate Cisco Meraki with Sophos XDR so that it sends alerts to Sophos for analysis.
This page gives you an overview of the integration.
Cisco Meraki product overview
Cisco Meraki offers a cloud-managed firewall solution that integrates with Meraki's broader suite of network products. The platform itself provides centralized management, visibility, and control.
What we ingest
We ingest Cisco Meraki (syslog) exactly as the Cisco Meraki dashboard sends it for the roles and products you enable. Do not reorder fields, change delimiters, or transform messages in ways that alter Cisco Meraki’s published layout. Use the Cisco Meraki documentation (for example, Syslog Event Types and Log Samples and Syslog Server Overview and Configuration for format, roles, and licensing.
Events are retained and searchable in the Sophos XDR Data Lake and appear as Cisco Meraki when recognized.
Typical message shape (informational)
Cisco Meraki often prefixes lines with optional syslog metadata, a 0 or 1 flag, a high-resolution timestamp, the device name, a log type keyword (for example, flows, urls, events, security_event), and a key=value body. NAT-style flow lines may use the ip_flow_* family. The exact layout is defined by Cisco Meraki per log type.
What to enable
Point syslog at your Sophos XDR data collector using the IP, port, and protocol from data collector onboarding (often UDP syslog). Enable only the roles you need (for example, Flows, URLs, Security event log, Switch event log, Wireless event log). These role names depend on your product and license. On MX, per-rule flow logging is configured in the firewall UI when Flows is enabled.
Event and data types
We ingest the following event and data types from Cisco Meraki (syslog):
- Wired authentication: Switch
eventslines for port authentication (user identity, MAC, policy context). Normalized to authentication telemetry. - Intrusion detection / IPS (
security_event): IDS alert lines. Signatures, priority, direction, endpoints, allow/block, rule text, MAC context when present. Normalized to network IDS–style telemetry. - File / content inspection (
security_event):security_filtering_file_scanned. URL, hash, disposition, action, client MAC, threat name when supplied. Normalized to file-oriented telemetry. - HTTP and HTTPS URL activity:
urlslines. Method, URI (host, path, query, scheme), User-Agent when present, endpoints. Normalized to HTTP-style telemetry. - Content filtering blocks:
eventscontent filtering blocks. Blocked URL, category, server, client MAC. Normalized to HTTP-style telemetry. - Flows:
flowslines. Allow/deny, endpoints, ports, protocol, MAC when present. Normalized to netflow-style telemetry. - Firewall / L7 / VPN firewall: Log types whose name includes
firewall. Tuples, allow/block from decision or pattern, IPv4 or IPv6. Normalized to netflow-style telemetry. - NAT flow lifecycle:
ip_flow_start,ip_flow_stop,ip_flow_end when present. Translated addresses and ports, protocol, session endpoints. Normalized to netflow-style telemetry. - Wireless and Air Marshal:
airmarshal_eventsand many APeventsvariants. Ingested, often as generic telemetry rather than the specialized categories above. - Other Meraki syslog: Additional types remain ingested and searchable, commonly as generic telemetry.
Alerts ingested in full
We ingest all security events returned by the query set up here: Get Organization Appliance Security Events.
These are the same events as ingested by the Cisco Meraki API integration.
We also ingest additional Event logs and some Flow alerts.
Data provided by this integration
Data provided by Cisco Meraki (syslog) gets normalized to the following schemas:
authfilehttpnetflownids
For more information about using schemas in Data Lake Search, see Schemas and logical types.