Version 2.0.0 of the Splunk Add-on for Cisco Meraki was released on August 22, 2022.
|Splunk Enterprise platform versions||8.1, 8.2, 9.0
Splunk Cloud (Classic Stack with IDM and Search Head on Victoria)
|Vendor Products||Cisco Meraki API v1.22.0|
The field alias functionality is compatible with the current version of this add-on. The current version of this add-on does not support older field alias configurations.
For more information about the field alias configuration change, refer to the Splunk Enterprise Release Notes.
This release includes the following changes:
- eventData.ip is mapped to src_ip for dhcp_lease instead of to dest_ip. eventData.server_ip mapped to dest_ip. If content was built on the fields, review and update as needed.
- Support for the China Service Region has been added to Configuration > Organization
Refer to "Information for Users in China" (https://documentation.meraki.com/General_Administration/Support/Information_for_Users_in_China) for more information about the service
- Air Marshal scan results: An Air Marshal input has been added. The input uses the getNetworkWirelessAirMarshal endpoint (https://developer.cisco.com/meraki/api-v1/#!get-network-wireless-air-marshal) to get scan results.
NOTE: Data loaded to Splunk is limited to what is exposed in the endpoint. Particularly, there are no SSIDs categorization as in Dashboard GUI - as Rogue SSIDs, Other SSIDs, Spoofs, etc. This release is compatible with the following software, CIM versions, and platforms.
- Splunk Add-on for Cisco Meraki field mapping changes:
|Source-type||meraki_event_type||Fields added||Fields removed|
Version 2.0.0 of the Splunk Add-on for Cisco Meraki contains the following fixed issues.
Version 2.0.0 of the Splunk Add-on for Cisco Meraki the following known issues.
Third-party software attributions
Lookups for the Splunk Add-on for Cisco Meraki
Release notes history
This documentation applies to the following versions of Splunk® Supported Add-ons: released