TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: API Log Source
ENVIRONMENT: Cisco Meraki Cloud
SUMMARY: Configuration Guide for Meraki Cloud Log Ingestion
Vendor Information
Vendor |
Cisco |
---|---|
Supported Model Name/Number |
Meraki Cloud |
Supported License Version(s) |
Advanced Security |
Collection Method |
REST API |
Provider Name |
MerakiCloud |
Additional Information |
|
Device Configuration Checklist
- Log in to the Meraki Cloud Administrator Portal.
- Obtain an API Key.
- In the Huntress Console (from the Account-Level Dashboard), navigate to SIEM -> Source Management.
- The Cisco Meraki Cloud Source option is not available at the Organization-Level because you are asked to map the Huntress equivalent organization later in the setup.
- Select the "Categories" tab below the Source Management header.
- Select View Details on the Meraki Cloud source card.
- Select the green +Add button to create a new Meraki Cloud configuration.
- Enter the details of the configuration as needed, including the API key obtained in the first two steps. Save the configuration.
- After saving, you'll be directed to the Configure page where you will need to map the organizations between Cisco Meraki Cloud and Huntress. For each Meraki Cloud Organization, select a Huntress equivalent organization from the dropdown.
- Once the organizations have been mapped, the Meraki Cloud configuration page will show the mapped log sources. Clicking on a source organization will bring you to a query page with the relevant logs.