LSO : Syslog - Cisco Meraki (Mapping Doc)

This document explains the changes required to apply new Message Processing Engine (MPE) rules developed during the Log Source Optimization (LSO) project for the Syslog - Cisco Meraki log source type. 

Vendor Documentation

Prerequisites

  • Download and apply the Knowledge Base. For more information, see KB Synchronization Settings for LSO.

  • Enable the new MPE rules in the LogRhythm System Monitor.Select log source type Syslog - Cisco Meraki.Enable log processing policy LogRhythm Default v2.0.For details on how to enable LogRhythm Default v2.0, see Apply LogRhythm Default v2.0 on a Log Source.

Supported Log Messages

The following table lists the log message types supported in the current MPE rules. Each page contains detailed information on parsing changes and new log processing settings.

Log Message Type

Event Type

Carrier Change Event

Network Interface Changed State

Catch All : Level 1

General Information

Cisco AnyConnect VPN Event

VPN Traffic

Events

System Events

File Scanned

Scan Activity

Firewall Messages

Traffic Information

Flow Messages

IP Flow Events

General Event Messages

Event Occurred

Intrusion Detection Messages

IDS Event

Last Message Repeated

Last Message Repeated

Random Event Messages

System Events

Security Event

General Attack Activity

Site-To-Site VPN Event

General VPN Information

Sniffer Rule Event

General Event Log Information

Switch Port Messages

Switch Information

URL Messages

Traffic Allowed by Proxy

Log Processing Policy Updates

This section details log processing policy updates made to AIE Rules, system reports, system investigations, system report templates, and system tails as part of LSO.

Updates to AIE Rules

  • No changes

Updates to System Reports

  • No changes

Updates to System Investigations

  • No changes

Updates to System Report Templates

  • No changes

Updates to System Tails

  • No changes