<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Meraki syslog messages are confusing in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424208#M7040</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Since meraki logs seem to truncate the useful portion of most messages, I am sending "flows, urls and security events" to a syslog server.&lt;BR /&gt;&lt;BR /&gt;However, "flow" isnt really a helpful category. Apparently some things have been split into more useful labels&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Adrian4_0-1726043789996.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263678i96EB64B78741FC91/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;but im still seeing thousands of messages marked as "flow" - what does this actually mean? &lt;/P&gt;&lt;P&gt;Another issue I have is finding the content filter logs. Int eh dashboard they are clearly marked as &lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Filtering&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;Content filtering blocked URL&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;and there are lots of logs, but I cant see anything int eh syslog server with "content filter" in the message. How do I find these?&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 08:38:43 GMT</pubDate>
    <dc:creator>Adrian41</dc:creator>
    <dc:date>2024-09-11T08:38:43Z</dc:date>
    <item>
      <title>Meraki syslog messages are confusing</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424208#M7040</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Since meraki logs seem to truncate the useful portion of most messages, I am sending "flows, urls and security events" to a syslog server.&lt;BR /&gt;&lt;BR /&gt;However, "flow" isnt really a helpful category. Apparently some things have been split into more useful labels&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Adrian4_0-1726043789996.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263678i96EB64B78741FC91/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;but im still seeing thousands of messages marked as "flow" - what does this actually mean? &lt;/P&gt;&lt;P&gt;Another issue I have is finding the content filter logs. Int eh dashboard they are clearly marked as &lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN&gt;Filtering&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN&gt;Content filtering blocked URL&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;and there are lots of logs, but I cant see anything int eh syslog server with "content filter" in the message. How do I find these?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 08:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424208#M7040</guid>
      <dc:creator>Adrian41</dc:creator>
      <dc:date>2024-09-11T08:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki syslog messages are confusing</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424209#M7041</link>
      <description>&lt;P&gt;What mx device and firmware you have?&lt;/P&gt;&lt;P&gt;Do you also have a MR ? Mr should still send flow logging&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Event_Types_and_Log_Samples" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Event_Types_and_Log_Samples&lt;/A&gt;&lt;/P&gt;&lt;P&gt;A flow is basically every new session a client makes&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.meraki.com/t5/Wireless/What-Is-Flows/td-p/36277" target="_blank"&gt;https://community.meraki.com/t5/Wireless/What-Is-Flows/td-p/36277&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424209#M7041</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2024-09-11T09:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki syslog messages are confusing</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424210#M7042</link>
      <description>&lt;P&gt;hello,&lt;BR /&gt;we have mostly MX250's on &lt;SPAN&gt;18.211.2   &lt;/SPAN&gt; and MR46's&lt;BR /&gt;&lt;BR /&gt;basically, I want to be able to whatever traffic is being blocked. Id like to know, what did the blocking (was it the content filter or firewall? if its a firewall rule, which rule), also exactly what url / ip /whatever was blocked.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Right now I have lots of logs that say "flows deny" with a src/dst ip, a mac and a protocol. - What is that? Is that a firewall rule? which firewall? which rule?&lt;BR /&gt;&lt;BR /&gt;In my MX firewall rules I have selected certain ones to log to syslog  how do i find those in the logs?&lt;BR /&gt;&lt;BR /&gt;how do i see what the content filter is blocking?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424210#M7042</guid>
      <dc:creator>Adrian41</dc:creator>
      <dc:date>2024-09-11T09:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki syslog messages are confusing</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424211#M7043</link>
      <description>&lt;P&gt;Adrian,&lt;/P&gt;&lt;P&gt;For the "Flows Deny" that sounds like the ACLs in effect. This includes the switching ACLs and MR ACLs.  Meraki will not block any LAN/Outbound connections unless you specifically state to do so. By default, it's in an allow state. However, for the MRs, it will automatically block LAN connections. You'd have to go into Wireless -&amp;gt; Firewall &amp;amp; Traffic Shaping, then check those rules.&lt;/P&gt;&lt;P&gt;For all inbound traffic being blocked, you can view the Security Center in Security &amp;amp; SD-Wan -&amp;gt; Security Center. You can see what is being blocked through the content filter, and what is being blocked in general based on pre-defined rules via Snort. You can also see these logs in Network-Wide -&amp;gt; Event Log.&lt;/P&gt;&lt;P&gt;Hopefully this information helps.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 14:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424211#M7043</guid>
      <dc:creator>ntuccillo</dc:creator>
      <dc:date>2024-09-11T14:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki syslog messages are confusing</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424212#M7044</link>
      <description>&lt;P&gt;Hi, thanks for the reply - but this is about syslog messages.&lt;BR /&gt;&lt;BR /&gt;If the meraki logs didnt truncate the messages, then there would be no need for the syslog server but since they do, I need to understand what is generating the messages (which firewall, which rule, whats the content filter doing?).&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 14:16:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424212#M7044</guid>
      <dc:creator>Adrian41</dc:creator>
      <dc:date>2024-09-11T14:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Meraki syslog messages are confusing</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424213#M7045</link>
      <description>&lt;P&gt;My apologies, I need to read better. For "Flows Deny", I am 99% certain that it's going to be an inbound connection from an external IP. We get tons of them every day. I can't give you any other information on Syslog. We let our SIEM translate it. I'm sorry.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 14:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/meraki-syslog-messages-are-confusing/m-p/5424213#M7045</guid>
      <dc:creator>ntuccillo</dc:creator>
      <dc:date>2024-09-11T14:43:08Z</dc:date>
    </item>
  </channel>
</rss>

