↳ GitHub sourceConnector

Cisco Meraki Events (using REST API) (via Codeless Connector Framework)

Description

The [Cisco Meraki](https://aka.ms/ciscomeraki) connector allows you to easily connect your Cisco Meraki organization events (Security events, Configuration Changes and API Requests) to Microsoft Sentinel. The data connector uses the [Cisco Meraki REST API](https://developer.cisco.com/meraki/api-v1/#!get-organization-appliance-security-events) to fetch logs and supports DCR-based [ingestion time transformations](https://docs.microsoft.com/azure/azure-monitor/logs/custom-logs-overview) that parses the received data and ingests into ASIM and custom tables in your Log Analytics workspace. This data connector benefits from capabilities such as DCR based ingestion-time filtering, data normalization. In addition to the ASIM-normalized events, this connector also ingests Cisco Meraki Dashboard inventory and wireless security data into custom tables - Organizations, Network Clients, Organization Networks, and wireless Air Marshal (rogue access point) events. **Supported ASIM schema:** 1. Network Session 2. Web Session 3. Audit Event
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Configuration steps for the Cisco Meraki Dashboard API
Follow the instructions below to obtain your Cisco Meraki API credentials.
Connect Cisco Meraki organizations to Microsoft Sentinel
This connector supports multi-tenant ingestion. Add one connection per Cisco Meraki organization; each connection ingests events for that organization in parallel. Use the grid below to review existing connections or add a new one.
Add Connection
Connect a Cisco Meraki organization
API Base URL
Organization ID
API Key
Data Types
Organizations
Organization Networks
Network Clients
Air Marshal Events
API Requests (ASIM Web Session)
Configuration Changes (ASIM Audit Event)
Security Events / IDS (ASIM Network Session)

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CiscoMerakiConnector
Additional source files 2Solutions/Cisco Meraki Events via REST API/Data Connectors/CiscoMerakiMultiRule_ccp/CiscoMeraki_ConnectorDefinition.jsonsource ↗Solutions/Cisco Meraki Events via REST API/Data/Solution_Cisco Meraki Events via REST API.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.