<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk intergration in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422971#M10771</link>
    <description>&lt;P&gt;I haven't seen anything for Splunk with regard to Systems Manager.  Not that it can not be done, but the integrations I have seen have been based around MX.&lt;/P&gt;&lt;P&gt;Check out this developer communities post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.cisco.com/community/developer/meraki/blog/2016/07/05/merakifying-splunk" target="_self" rel="nofollow noopener noreferrer"&gt;https://communities.cisco.com/community/developer/meraki/blog/2016/07/05/merakifying-splunk&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jul 2018 03:16:31 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2018-07-04T03:16:31Z</dc:date>
    <item>
      <title>Splunk intergration</title>
      <link>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422970#M10770</link>
      <description>&lt;P&gt;Has anyone been able to integrate all the logs produced from Systems Manger to be pushed into Splunk or something similar. Any help or being pointed into the right direction would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jul 2018 01:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422970#M10770</guid>
      <dc:creator>Phil15</dc:creator>
      <dc:date>2018-07-04T01:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk intergration</title>
      <link>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422971#M10771</link>
      <description>&lt;P&gt;I haven't seen anything for Splunk with regard to Systems Manager.  Not that it can not be done, but the integrations I have seen have been based around MX.&lt;/P&gt;&lt;P&gt;Check out this developer communities post:&lt;/P&gt;&lt;P&gt;&lt;A href="https://communities.cisco.com/community/developer/meraki/blog/2016/07/05/merakifying-splunk" target="_self" rel="nofollow noopener noreferrer"&gt;https://communities.cisco.com/community/developer/meraki/blog/2016/07/05/merakifying-splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jul 2018 03:16:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422971#M10771</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2018-07-04T03:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk intergration</title>
      <link>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422972#M10772</link>
      <description>&lt;P&gt;Hello Phil,&lt;/P&gt;&lt;P&gt;there is an option to that which is Splunk  Add-On for Cisco Meraki Operations, Even I am trying in my POC environment this, will give more views if I found anything further. Please go through with below links you find something.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/6201/#/overview" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunkbase.splunk.com/app/6201/#/overview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Meraki/Setup" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/AddOns/released/Meraki/Setup&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 18:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422972#M10772</guid>
      <dc:creator>Basavaraj2</dc:creator>
      <dc:date>2022-02-17T18:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk intergration</title>
      <link>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422973#M10773</link>
      <description>&lt;P&gt;I am wondering if you were able to make it work&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2022 22:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422973#M10773</guid>
      <dc:creator>Faisal Mehmood</dc:creator>
      <dc:date>2022-08-11T22:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk intergration</title>
      <link>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422974#M10774</link>
      <description>&lt;P&gt;With many integrations, there's two options:&lt;/P&gt;&lt;P&gt;PULL: Where the data is PULLED from Meraki, using the APIs&lt;/P&gt;&lt;P&gt;PUSH: where, using web hooks, syslog, data is pushed from Meraki&lt;/P&gt;&lt;P&gt;The Splunk integration appears to be a PULL integration, according to the APIs that it uses:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://api.meraki.com/api/v1/organizations/:org/devices/statuses/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://api.meraki.com/api/v1/organizations/:org/devices/statuses/&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://api.meraki.com/api/v1/organizations/:org/uplinks/statuses/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://api.meraki.com/api/v1/organizations/:org/uplinks/statuses/&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://api.meraki.com/api/v1/organizations/:org/devices/uplinksLossAndLatency" target="_blank" rel="nofollow noopener noreferrer"&gt;https://api.meraki.com/api/v1/organizations/:org/devices/uplinksLossAndLatency&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://api.meraki.com/api/v1/organizations/:org/networks" target="_blank" rel="nofollow noopener noreferrer"&gt;https://api.meraki.com/api/v1/organizations/:org/networks&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;A href="https://api.meraki.com/api/v1/networks/:network/devices" target="_blank" rel="nofollow noopener noreferrer"&gt;https://api.meraki.com/api/v1/networks/:network/devices&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I note that the SM endpoints are not included in there&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HOWEVER, whilst not impossible, there's a little work for you to do. It looks like Splunk can ingest data using any REST based API:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/getting-data-from-your-rest-apis-into-splunk.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.splunk.com/en_us/blog/tips-and-tricks/getting-data-from-your-rest-apis-into-splunk.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And this starts with a simple form to fill in:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.jpeg" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/262859i79B0C51A4DC75139/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.jpeg" alt="image.jpeg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Don't forget that Meraki uses a custom parameter for Auth, &lt;/P&gt;&lt;PRE&gt;X-Cisco-Meraki-API-Key: &amp;lt;secret key&amp;gt;&lt;/PRE&gt;&lt;P&gt;Which should go into your headers.&lt;/P&gt;&lt;P&gt;Let me know how you get on....&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2022 09:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/splunk-intergration/m-p/5422974#M10774</guid>
      <dc:creator>Arthur Dent</dc:creator>
      <dc:date>2022-08-17T09:32:06Z</dc:date>
    </item>
  </channel>
</rss>

