<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meraki to Microsoft Sentinel integration using API in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415631#M5215</link>
    <description>&lt;P&gt;Yes, I’m using &lt;A href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/azuresentinel.azure-sentinel-solution-ciscomerakinativepoller?tab=overview" target="_self" rel="nofollow noopener noreferrer"&gt;Cisco Meraki Events via REST API&lt;/A&gt; data connector in sentinel. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks for the responses. I’m not able to view which API endpoint the connector is querying as it is an out-of-the-box connector provided by Microsoft. I'll see if there is documentation available related to this. And yes, I’ll keep the API key safe.&lt;/P&gt;</description>
    <pubDate>Thu, 16 May 2024 19:42:00 GMT</pubDate>
    <dc:creator>Mathews</dc:creator>
    <dc:date>2024-05-16T19:42:00Z</dc:date>
    <item>
      <title>Meraki to Microsoft Sentinel integration using API</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415629#M5213</link>
      <description>&lt;P&gt;Trying to integrate Meraki with Microsoft Sentinel using API. Sentinel has a data connector that helps with this and requires the API key and organization ID. It gets connected, and logs are coming in.&lt;/P&gt;&lt;P&gt;Now, the questions:&lt;/P&gt;&lt;P&gt;1) Are there any configurations required at the individual Meraki devices' end to ensure this API method retrieves logs from all connected devices? There are many MX devices, access points, and switches. The API is generated from the dashboard as per &lt;A href="https://documentation.meraki.com/General_Administration/Other_Topics/Cisco_Meraki_Dashboard_API" target="_self" rel="nofollow noopener noreferrer"&gt;documentation&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2) Are the IDS/Security events collected via API the same as when collected via syslog method ?&lt;/P&gt;&lt;P&gt;3) What are the important considerations when opting for API collection instead of syslog collection?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2024 19:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415629#M5213</guid>
      <dc:creator>Mathews</dc:creator>
      <dc:date>2024-05-15T19:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki to Microsoft Sentinel integration using API</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415630#M5214</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm not familiar with using Microsoft Sentinel for the API. Are you looking at something like &lt;A href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/azuresentinel.azure-sentinel-solution-ciscomerakinativepoller?tab=overview" target="_self" rel="nofollow noopener noreferrer"&gt;Cisco Meraki Events via REST API&lt;/A&gt;? Or like &lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/cisco-meraki" target="_self" rel="nofollow noopener noreferrer"&gt;Cisco Meraki connector for Microsoft Sentinel &lt;/A&gt;&lt;/P&gt;&lt;P&gt;1) Not from individual Meraki devices. However, depending on the API endpoint you are using you may need to enter information such as a VLAN ID, serial number, port, etc. Those are just parameters of some API endpoints. &lt;/P&gt;&lt;P&gt;2) Yes, if using one of these endpoints: &lt;SPAN&gt;getOrganizationApplianceSecurityEvents or getNetworkApplianceSecurityEvents. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3) This depends on how everything is formatted with Microsoft Sentinel. What comes to mind is how the information will be processed and if formatting is important. Lastly, keep your API key safe. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let me know if you have any questions. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 19:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415630#M5214</guid>
      <dc:creator>MariaP8</dc:creator>
      <dc:date>2024-05-16T19:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki to Microsoft Sentinel integration using API</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415631#M5215</link>
      <description>&lt;P&gt;Yes, I’m using &lt;A href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/azuresentinel.azure-sentinel-solution-ciscomerakinativepoller?tab=overview" target="_self" rel="nofollow noopener noreferrer"&gt;Cisco Meraki Events via REST API&lt;/A&gt; data connector in sentinel. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks for the responses. I’m not able to view which API endpoint the connector is querying as it is an out-of-the-box connector provided by Microsoft. I'll see if there is documentation available related to this. And yes, I’ll keep the API key safe.&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 19:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415631#M5215</guid>
      <dc:creator>Mathews</dc:creator>
      <dc:date>2024-05-16T19:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki to Microsoft Sentinel integration using API</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415632#M5216</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;Hi,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;From &lt;A href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/azuresentinel.azure-sentinel-solution-ciscomerakinativepoller?tab=overview" target="_self" rel="nofollow noopener noreferrer"&gt;Cisco Meraki Events via REST API&lt;/A&gt;: &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;The Cisco Meraki Events via REST API solution for Microsoft Sentinel enables you to easily ingest the following events from Cisco Meraki MX security appliance to Microsoft Sentinel using Cisco Meraki API:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;1. Organization Appliance Security Events&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="3"&gt;2. Organization Api Requests&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="3"&gt;3. Organization Configuration Changes&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;1. Based on the information above I would expect this to use most GET &lt;A href="https://developer.cisco.com/meraki/api-v1/api-index/" target="_self" rel="nofollow noopener noreferrer"&gt;organization level API calls. &lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;- when clicking this link type "/organization" into the first search box. &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;2. It also specifically calls out the Organization Appliance Security Events which is probably this call: &lt;A href="https://developer.cisco.com/meraki/api-v1/get-organization-appliance-security-events/" target="_self" rel="nofollow noopener noreferrer"&gt;&lt;SPAN&gt;getOrganizationApplianceSecurityEvents. &lt;/SPAN&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3"&gt;&lt;SPAN&gt;3. Refers to the changelog found under &lt;STRONG&gt;Organization &amp;gt; Changelog. &lt;/STRONG&gt;This seems to refer to this API endpoint: &lt;A href="https://developer.cisco.com/meraki/api-v1/get-organization-configuration-changes/" target="_self" rel="nofollow noopener noreferrer"&gt;getOrganizationConfigurationChanges&lt;/A&gt;. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3" color="#000000"&gt;But as you stated, it's always good to get confirmation from Microsoft. &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="helvetica" size="3" color="#000000"&gt;Feel free to reach back out should you need anything else. &lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 22:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415632#M5216</guid>
      <dc:creator>MariaP8</dc:creator>
      <dc:date>2024-05-16T22:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki to Microsoft Sentinel integration using API</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415633#M5217</link>
      <description>&lt;P&gt;Hello, this may help you. &lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cisco%20Meraki%20Events%20via%20REST%20API/Data%20Connectors/CiscoMerakiMultiRule_ccp/dataConnectorPoller.json" target="_blank" rel="nofollow noopener noreferrer"&gt;Azure-Sentinel/Solutions/Cisco Meraki Events via REST API/Data Connectors/CiscoMerakiMultiRule_ccp/dataConnectorPoller.json at master · Azure/Azure-Sentinel · GitHub&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 19:07:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-to-microsoft-sentinel-integration-using-api/m-p/5415633#M5217</guid>
      <dc:creator>austinmorphies</dc:creator>
      <dc:date>2025-05-12T19:07:12Z</dc:date>
    </item>
  </channel>
</rss>

