<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meraki event querying and analysis tools? (incl. 3rd party?) in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-event-querying-and-analysis-tools-incl-3rd-party/m-p/5422823#M6818</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;[...] it seems like you are mainly focused on events.&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Correct. I.e. don't need "visual" or "simple to use" but rather - a splunk-like QL for Meraki events that is simple to set up and maintain and ideally wouldn't require me to set up some sort of a forwarder (like a syslog server).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(E.g. all that &lt;A href="https://www.google.com/search?q=how+to+set+up+Meraki+events+in+Datadog" target="_self" rel="nofollow noopener noreferrer"&gt;Datadog seems to need&lt;/A&gt; to start receiving logs into their system is an API key. That's already much better than setting up a syslog server.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In other words, the main question remains:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is the simplest way to use a decent Query Language for Meraki events? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Perhaps it's Logic Monitor or &lt;A href="https://www.google.com/search?q=how+to+set+up+Meraki+events+in+Datadog" target="_self" rel="nofollow noopener noreferrer"&gt;Datadog&lt;/A&gt; or New Relic - or Splunk, all of which have integrations. But which one, in terms of QL maturity and overall value?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(Ideally the answer would come come from someone who has tried a few and zeroed in on something that worked.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Aug 2024 00:17:29 GMT</pubDate>
    <dc:creator>alexeig</dc:creator>
    <dc:date>2024-08-25T00:17:29Z</dc:date>
    <item>
      <title>Meraki event querying and analysis tools? (incl. 3rd party?)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-event-querying-and-analysis-tools-incl-3rd-party/m-p/5422821#M6816</link>
      <description>&lt;P&gt;Basically I am looking for a Splunk-like tool for Meraki events across 20+ networks and MX devices, 60+ switches. Given I have next to zero money aka budget (that I know of, haha), and next to zero time to maintain that tool (wearing lots of other hats) - the focus is on the simplicity, ease of maintenance. (Splunk is a bear to maintain - and can get expensive fast.) Need something simple yet where an SQL-like query would give me a fast answer to "top 10 networks with most site-to-site auto-VPN failures" and then chart the results over e.g. 3 years.&lt;/P&gt;&lt;P&gt;If you have a suggestion, &lt;STRONG&gt;please include a screenshot&lt;/STRONG&gt; (or a link) to a dashboard or report (or other KO) example of how this tool actually works, what results it produces.&lt;/P&gt;&lt;P&gt;Context:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Given Meraki's focus on ease of use and putting everything in the cloud, I was surprised to find out just how limited event search in Meraki is. Can't search for specific strings or regex in the events. Can't search across 2+ networks. Can't even export a full CSV of a specific log, or all logs. (Seriously?) Forget any sort of analytics other than what Meraki dashboards already provide.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Given the (event) data is already in Meraki &lt;/SPAN&gt;&lt;SPAN&gt;cloud (even if with very limited retention), I thought maybe there are good integrations with other cloud-based analytics and o11y tools - Splunk, Azure Log Analytics, Datadog, New Relic - that use the data in place... Authorize, connect, and Bob's your uncle? But... no:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;there's not a single one letting me search the existing data in place - must &lt;EM&gt;forward&lt;/EM&gt; first to a different tool with its own storage. Hmmm, OK.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;There are some integrations like &lt;A href="https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/cisco-meraki" target="_self" rel="nofollow noopener noreferrer"&gt;Cisco Meraki connector for Microsoft Sentinel&lt;/A&gt; - yet that is anything but simple: set up a syslog server, Sentinel agent, all that - apparently with a number of &lt;A href="https://www.reddit.com/r/meraki/comments/n3rq6s/comment/gww2zh2/" target="_blank" rel="noopener nofollow noreferrer"&gt;seemingly critical issues&lt;/A&gt; that (a) make the solution anything but simple and seem to be a recipe for a mountain of technical debt, and (b) require a purchase of another product we don't have (Sentinel) and not sure we need.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;there're Splunk Web &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Meraki/Setup" target="_blank" rel="noopener nofollow noreferrer"&gt;Add-on for Cisco Meraki&lt;/A&gt;, and &lt;A href="https://splunkbase.splunk.com/app/5580" target="_blank" rel="noopener nofollow noreferrer"&gt;Splunk Add-on for Cisco Meraki&lt;/A&gt;, both with very sparse information - e.g. no examples of KOs, reports, dashboards - and I am hesitant to spend weeks or months on setting up a POC, only to find out there're insurmountable limitations.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;P.S. Please help me with the subject / title of this thread. What should it be if I am looking for a substantial upgrade to Meraki's current event retention, querying and analysis functionality? "Log aggregation" doesn't quite sound right. SIEM? This isn't about security - more about o11y and analytics that's not limited to security. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 17:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-event-querying-and-analysis-tools-incl-3rd-party/m-p/5422821#M6816</guid>
      <dc:creator>alexeig</dc:creator>
      <dc:date>2024-08-21T17:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki event querying and analysis tools? (incl. 3rd party?)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-event-querying-and-analysis-tools-incl-3rd-party/m-p/5422822#M6817</link>
      <description>&lt;P&gt;Hey &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/89838"&gt;@alexeig&lt;/A&gt; &lt;/P&gt;&lt;P&gt;It sounds like a syslog server is what you need ultimately. Event logs are one of the different data points that is exported towards them, it seems like you are mainly focused on events.&lt;BR /&gt;If you are wanting something more visual and simple, I would recommend browsing apps.meraki.io for a solution. One good solution you can look into is LogicMonitor &lt;A href="https://apps.meraki.io/en-US/apps/420402/logicmonitor-%7C-lm-envision#features" target="_blank" rel="noopener nofollow noreferrer"&gt;https://apps.meraki.io/en-US/apps/420402/logicmonitor-%7C-lm-envision#features&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;A whole list of different options can be viewed here: &lt;A href="https://apps.meraki.io/en-US/listing?cat=99861&amp;amp;page=1" target="_blank" rel="nofollow noopener noreferrer"&gt;https://apps.meraki.io/en-US/listing?cat=99861&amp;amp;page=1&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hopefully this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 15:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-event-querying-and-analysis-tools-incl-3rd-party/m-p/5422822#M6817</guid>
      <dc:creator>KH6</dc:creator>
      <dc:date>2024-08-22T15:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki event querying and analysis tools? (incl. 3rd party?)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-event-querying-and-analysis-tools-incl-3rd-party/m-p/5422823#M6818</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;[...] it seems like you are mainly focused on events.&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;Correct. I.e. don't need "visual" or "simple to use" but rather - a splunk-like QL for Meraki events that is simple to set up and maintain and ideally wouldn't require me to set up some sort of a forwarder (like a syslog server).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(E.g. all that &lt;A href="https://www.google.com/search?q=how+to+set+up+Meraki+events+in+Datadog" target="_self" rel="nofollow noopener noreferrer"&gt;Datadog seems to need&lt;/A&gt; to start receiving logs into their system is an API key. That's already much better than setting up a syslog server.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In other words, the main question remains:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is the simplest way to use a decent Query Language for Meraki events? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Perhaps it's Logic Monitor or &lt;A href="https://www.google.com/search?q=how+to+set+up+Meraki+events+in+Datadog" target="_self" rel="nofollow noopener noreferrer"&gt;Datadog&lt;/A&gt; or New Relic - or Splunk, all of which have integrations. But which one, in terms of QL maturity and overall value?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(Ideally the answer would come come from someone who has tried a few and zeroed in on something that worked.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Aug 2024 00:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-event-querying-and-analysis-tools-incl-3rd-party/m-p/5422823#M6818</guid>
      <dc:creator>alexeig</dc:creator>
      <dc:date>2024-08-25T00:17:29Z</dc:date>
    </item>
  </channel>
</rss>

