↳ GitHub sourceConnector
Cisco Meraki Events (using REST API) (via Codeless Connector Framework)
Description
The [Cisco Meraki](https://aka.ms/ciscomeraki) connector allows you to easily connect your Cisco Meraki organization events (Security events, Configuration Changes and API Requests) to Microsoft Sentinel. The data connector uses the [Cisco Meraki REST API](https://developer.cisco.com/meraki/api-v1/#!get-organization-appliance-security-events) to fetch logs and supports DCR-based [ingestion time transformations](https://docs.microsoft.com/azure/azure-monitor/logs/custom-logs-overview) that parses the received data and ingests into ASIM and custom tables in your Log Analytics workspace. This data connector benefits from capabilities such as DCR based ingestion-time filtering, data normalization.
In addition to the ASIM-normalized events, this connector also ingests Cisco Meraki Dashboard inventory and wireless security data into custom tables - Organizations, Network Clients, Organization Networks, and wireless Air Marshal (rogue access point) events.
**Supported ASIM schema:**
1. Network Session
2. Web Session
3. Audit Event
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Configuration steps for the Cisco Meraki Dashboard API
Follow the instructions below to obtain your Cisco Meraki API credentials.
Connect Cisco Meraki organizations to Microsoft Sentinel
This connector supports multi-tenant ingestion. Add one connection per Cisco Meraki organization; each connection ingests events for that organization in parallel. Use the grid below to review existing connections or add a new one.
Add Connection
Connect a Cisco Meraki organization
API Base URL
Organization ID
API Key
Data Types
Organizations
Organization Networks
Network Clients
Air Marshal Events
API Requests (ASIM Web Session)
Configuration Changes (ASIM Audit Event)
Security Events / IDS (ASIM Network Session)
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
CiscoMerakiConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC