Chaps and chapesses,
There's not going to be any difference between setting up data sources for a Meraki and a Meraki MX... is there? Usual Cisco/Meraki/Default/Syslog settings on the SIEM data source?
(Customer has one and says it's sending data: tcpdump and the data source on the ESM say otherwise)
Kind regards
James
putting the parser aside, you should at least get data on the ERC. if no tcpdump output, then there's something wrong because you are getting any events.
There have been no reported issues to SIEM Support about this so we're not aware of any issues. However, if the Meraki configuration says it should send syslog to SIEM on a certain port and it's not sending any packets - that would be an issue on the Meraki side.
See if you can check the outbound route from the Meraki towards the SIEM receiver - perhaps it's missing a route or it has the wrong pathing or vlan tagging on that route?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA