LSO : Syslog - Cisco Meraki (Mapping Doc)
This document explains the changes required to apply new Message Processing Engine (MPE) rules developed during the Log Source Optimization (LSO) project for the Syslog - Cisco Meraki log source type.
Vendor Documentation
Prerequisites
- Download and apply the Knowledge Base. For more information, see KB Synchronization Settings for LSO.
- Enable the new MPE rules in the LogRhythm System Monitor.
- Select log source type Syslog - Cisco Meraki.
Enable log processing policy LogRhythm Default v2.0.
For details on how to enable LogRhythm Default v2.0, see Apply LogRhythm Default v2.0 on a Log Source.
Supported Log Messages
The following table lists the log message types supported in the current MPE rules. Each page contains detailed information on parsing changes and new log processing settings.
Log Message Type | Event Type |
---|---|
Carrier Change Event | Network Interface Changed State |
Catch All : Level 1 | General Information |
Cisco AnyConnect VPN Event | VPN Traffic |
Events | System Events |
File Scanned | Scan Activity |
Firewall Messages | Traffic Information |
Flow Messages | IP Flow Events |
General Event Messages | Event Occurred |
Intrusion Detection Messages | IDS Event |
Last Message Repeated | Last Message Repeated |
Random Event Messages | System Events |
Security Event | General Attack Activity |
Site-To-Site VPN Event | General VPN Information |
Sniffer Rule Event | General Event Log Information |
Switch Port Messages | Switch Information |
URL Messages | Traffic Allowed by Proxy |
Log Processing Policy Updates
This section details log processing policy updates made to AIE Rules, system reports, system investigations, system report templates, and system tails as part of LSO.
Updates to AIE Rules
- No changes
Updates to System Reports
- No changes
Updates to System Investigations
- No changes
Updates to System Report Templates
- No changes
Updates to System Tails
- No changes