<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security events count and type in Network Platform API</title>
    <link>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439905#M6263</link>
    <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/1069"&gt;@jscorb&lt;/A&gt;, thank you for your insights on the back-end side of this API call. I am definitely interested in the security appliances' events at the moment, however i am retrieving this data through a node.js backend. This still requires the same amount of API calls on this endpoint and they can't be made asynchronously as i have to wait for the "rel=next" link to be able to proceed.&lt;/P&gt;&lt;P&gt;I guess i was a bit optimistic in finding a faster way of providing this info, but it seems setting up a database to act as cache is necessary for these kinds of calls as to not overload the server with too many requests for the same resource as it seems redundant. &lt;SPAN class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jul 2024 14:40:26 GMT</pubDate>
    <dc:creator>omaralrafei1</dc:creator>
    <dc:date>2024-07-28T14:40:26Z</dc:date>
    <item>
      <title>Security events count and type</title>
      <link>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439903#M6261</link>
      <description>&lt;P&gt;I am interested in displaying the security events in an organization. I have found my way around the pagination for this specific call, however it seems a bit tedious to call this endpoint 40 times to get all of the events in a specific timespan (1 week gets me 40000 events).&lt;/P&gt;&lt;P&gt;Is there a more efficient way to tackle this? unless i need to maintain a database for my calls as cache &lt;SPAN class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 09:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439903#M6261</guid>
      <dc:creator>omaralrafei1</dc:creator>
      <dc:date>2024-07-25T09:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Security events count and type</title>
      <link>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439904#M6262</link>
      <description>&lt;P&gt;Assume you mean this call...&lt;/P&gt;&lt;P&gt;&lt;A href="https://developer.cisco.com/meraki/api-v1/get-organization-appliance-security-events/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://developer.cisco.com/meraki/api-v1/get-organization-appliance-security-events/&lt;/A&gt; &lt;/P&gt;&lt;P&gt;It will return up to a year of events. If you use the Meraki Python library it will handle the pagination for you.&lt;/P&gt;&lt;P&gt;Fwiw we gather this data on multiple organizations and store it for analysis/reporting, the call is run monthly for the previous month's events, and results appended to our long-term archive.&lt;/P&gt;&lt;P&gt;There are also non-appliance security events, these are retrieved per-network...&lt;/P&gt;&lt;P&gt;&lt;A href="https://developer.cisco.com/meraki/api-v1/get-network-events/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://developer.cisco.com/meraki/api-v1/get-network-events/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;...the events are returned most recent first, so we page until we get to events older than the month before and stop there.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 15:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439904#M6262</guid>
      <dc:creator>sungod</dc:creator>
      <dc:date>2024-07-25T15:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Security events count and type</title>
      <link>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439905#M6263</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/1069"&gt;@jscorb&lt;/A&gt;, thank you for your insights on the back-end side of this API call. I am definitely interested in the security appliances' events at the moment, however i am retrieving this data through a node.js backend. This still requires the same amount of API calls on this endpoint and they can't be made asynchronously as i have to wait for the "rel=next" link to be able to proceed.&lt;/P&gt;&lt;P&gt;I guess i was a bit optimistic in finding a faster way of providing this info, but it seems setting up a database to act as cache is necessary for these kinds of calls as to not overload the server with too many requests for the same resource as it seems redundant. &lt;SPAN class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2024 14:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439905#M6263</guid>
      <dc:creator>omaralrafei1</dc:creator>
      <dc:date>2024-07-28T14:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Security events count and type</title>
      <link>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439906#M6264</link>
      <description>&lt;P&gt;You do need to use both API calls to get &lt;EM&gt;all&lt;/EM&gt; the events, the second one I mention isn't appliance specific, but still is the only way to get certain appliance events that are security related (you can specify a filter so that it will only return appliance events).&lt;/P&gt;&lt;P&gt;These include...&lt;/P&gt;&lt;PRE class="lia-code-sample language-javascript"&gt;&lt;CODE&gt;{'category': 'Network-Based Application Recognition', 'type': 'nbar_block', 'description': 'Layer 7 firewall rule'}
{'category': 'Filtering', 'type': 'cf_block', 'description': 'Content filtering blocked URL'}
{'category': 'Filtering', 'type': 'sf_url_block', 'description': 'Security blocked URL'}
{'category': 'Filtering', 'type': 'sf_binary_block', 'description': 'Security blocked file'}
{'category': 'Intrusion Detection', 'type': 'ids_start', 'description': 'Intrusion detection started'}
{'category': 'Intrusion Detection', 'type': 'ids_error', 'description': 'Intrusion detection error'}
{'category': 'Intrusion Detection', 'type': 'ids_update', 'description': 'Intrusion detection rules update'}&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;...also events for AnyConnect.&lt;/P&gt;&lt;P&gt;This call will get you the current set of possible events, you can see which might be of interest to record...&lt;/P&gt;&lt;P&gt;&lt;A href="https://developer.cisco.com/meraki/api-v1/get-network-events-event-types/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://developer.cisco.com/meraki/api-v1/get-network-events-event-types/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2024 07:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/security-events-count-and-type/m-p/5439906#M6264</guid>
      <dc:creator>sungod</dc:creator>
      <dc:date>2024-07-29T07:17:00Z</dc:date>
    </item>
  </channel>
</rss>

