Splunk® Supported Add-ons

Splunk Add-on for Cisco Meraki

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Release Notes

Version 2.0.0 of the Splunk Add-on for Cisco Meraki was released on August 22, 2022.

Splunk Enterprise platform versions 8.1, 8.2, 9.0

Splunk Cloud (Classic Stack with IDM and Search Head on Victoria)

CIM 5.0.1
Platforms Platform independent
Vendor Products Cisco Meraki API v1.22.0

The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.

For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.

This release includes the following changes:

  • eventData.ip is mapped to src_ip for dhcp_lease instead of to dest_ip. eventData.server_ip mapped to dest_ip. If content was built on the fields, review and update as needed.
  • Support for the China Service Region has been added to Configuration > Organization

Refer to "Information for Users in China" (https://documentation.meraki.com/General_Administration/Support/Information_for_Users_in_China) for more information about the service

NOTE: Data loaded to Splunk is limited to what is exposed in the endpoint. Particularly, there are no SSIDs categorization as in Dashboard GUI - as Rogue SSIDs, Other SSIDs, Spoofs, etc. This release is compatible with the following software, CIM versions, and platforms.

  • Splunk Add-on for Cisco Meraki field mapping changes:
Source-type meraki_event_type Fields added Fields removed
['meraki:securityappliances'] dhcp_lease src_ip, duration user

Fixed issues

Version 2.0.0 of the Splunk Add-on for Cisco Meraki contains the following fixed issues.

Known issues

Version 2.0.0 of the Splunk Add-on for Cisco Meraki the following known issues.

Third-party software attributions


Last modified on 01 September, 2022
Lookups for the Splunk Add-on for Cisco Meraki
Release notes history

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters