Meraki GROK
Query
No standalone KQL detected in this source
View source on GitHubAbout this query
Explanation
The query is used to process a log file from a Cisco Meraki device and extract specific fields from the log messages. The log messages contain information such as timestamps, hostnames, IP addresses, ports, protocols, and request details. The extracted fields are then used to create new fields and remove unnecessary fields. Finally, the processed log data is sent to an Azure Log Analytics workspace for further analysis.
Details

Rod Trent
Released: November 4, 2020
Tables
CiscoMeraki
Keywords
DevicesIntuneUser
Operators
pathmatchoverwriteadd_fieldremove_fieldtargetstdout