Cisco Meraki

Configure the Cisco Meraki connector in Radiant Security to forward Meraki syslog traffic for AI triage.

Cisco Meraki forwards syslog to Radiant Security through the Radiant Agent. This guide covers adding the Cisco Meraki data feed in Radiant and configuring the Meraki dashboard to forward syslog to the agent.

Prerequisites

Add the data connector in Radiant Security

  1. Sign in to Radiant Security.

  2. From the navigation menu, select Settings > Data Connectors, then click + Add Connector.

  3. Search for and select Radiant Agent, then click Data Feeds.

  4. Under Select your data feeds, select Cisco Meraki, then click Credentials.

  5. Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g., Radiant Agent Integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.

  6. Click Add Connector.

Configure Cisco Meraki to forward syslog

Before starting, confirm the IP address of the Radiant Agent and the port configured to receive Cisco Meraki data. If you do not know the port, contact your Customer Success representative.

  1. Sign in to the Cisco Meraki dashboard.

  2. Navigate to Network-wide > Configure > General.

  3. Under Reporting, click Add a syslog server.

  4. Enter the Server IP and Port of the Radiant Agent.

  5. Under Roles, select URL, Flows, and Security events.

  6. Navigate to Security & SD-WAN > Configure > Firewall.

  7. Under Logging, set the drop-down to Enabled for each firewall rule whose traffic you want forwarded.

Verify ingestion

After Cisco Meraki begins forwarding, confirm alerts and events are reaching Radiant.

  1. In Radiant, navigate to Log Management.

  2. Filter by rs_connectorType:"cisco_meraki".

  3. Confirm recent alerts and events appear.

Allow several minutes for alerts and events to be parsed, indexed, and available for search.

Last updated

Was this helpful?