Azure-Sentinel/Solutions/CiscoMeraki
PrasadBoke d22096c9fc Solution packaged 2024-08-20 15:46:58 +05:30
..
Connector/MerakiConnector Changing the service endpoint of meraki domain url to api-mp to avoid the redirects 2022-02-07 20:28:14 +05:30
Data Connectors Custom Soln OMS Migration Packaging 2024-08-12 17:38:46 +05:30
Package Solution packaged 2024-08-20 15:46:58 +05:30
Parsers Delete CiscoMeraki.txt 2024-08-20 15:09:10 +05:30
Playbooks Text replaced to Microsoft Sentinel 2022-12-11 09:24:24 +05:30
Workbooks Update CiscoMerakiWorkbook.json 2022-05-24 18:17:54 +05:30
data Solution packaged 2024-08-20 15:08:56 +05:30
CiscoMerakiFlow.png Cisco Meraki Content Move + Solution Package 2021-09-07 10:07:41 -07:00
ConsolidatedTemplate.json Text replaced to Microsoft Sentinel 2022-12-11 09:24:24 +05:30
ReleaseNotes.md Solution packaged 2024-08-20 15:08:56 +05:30
SolutionMetadata.json Repackaging CiscoMeraki solution with Parser changes 2022-12-08 12:01:15 +05:30
linkedtemplate.json Cisco Meraki Content Move + Solution Package 2021-09-07 10:07:41 -07:00
readme.md Updating Readme file 2023-12-06 14:24:08 +05:30

readme.md

Cisco Meraki Logic Apps Custom Connector and Playbook Templates

meraki

Table of Contents

  1. Overview
  2. Deploy Custom Connector + 5 Playbook templates
  3. Authentication
  4. Prerequisites
  5. Deployment
  6. Post Deployment Steps
  7. References
  8. Limitations

Overview

Cisco Meraki connector connects to Cisco Meraki Dashboard API service endpoint and programmatically manages and monitors Meraki networks at scale.

Deploy Custom connector + 5 Playbook templates

This package includes:

  • Custom connector for Cisco Meraki.
  • Five playbook templates leverage Cisco Meraki custom connector.

You can choose to deploy the whole package : Connector + all five playbook templates, or each one seperately from it's specific folder.

Deploy to Azure Deploy to Azure Gov

Cisco Meraki documentation

Authentication

API Key Authentication

Prerequisites for using and deploying Custom connector + 5 playbooks

  1. Cisco Meraki API Key should be known to establish a connection with Cisco Meraki Custom Connector. Refer here
  2. Cisco Meraki Dashboard API service endpoint should be known. (e.g. https://{CiscoMerakiDomain}/api/{VersionNumber}) Refer here
  3. Organization name should be known. Refer here
  4. Network name should be known.Refer here
  5. Network Group Policy name should be known. Refer here

Deployment instructions

  1. Deploy the Custom connector and playbooks by clicking on "Deploy to Azure" button. This will take you to deploying an ARM Template wizard.
  2. Fill in the required parameters for deploying custom connector and playbooks
Parameter Description
For Playbooks
Block Device Client Playbook Name Enter the Block Device Client playbook name without spaces
Block IP Address Playbook Name Enter the Block IP Address playbook name without spaces
Block URL Playbook Name Enter the Block URL playbook name without spaces
Enrichment IP Address Playbook Name Enter the IP Address Enrichment playbook name without spaces
Enrichment URL Playbook Name Enter the URL Enrichment playbook name without spaces
Organization Name Enter the name of Organization
Network Name Enter the name of Network
Group Policy Enter the name of Group Policy
For Custom Connector
Cisco Meraki Connector Name Enter the name of Cisco Meraki custom connector without spaces
Service EndPoint Enter the Cisco Meraki Service End Point

Post-Deployment Instructions

a. Authorize API connections

  • Once deployment is complete, go under deployment details and authorize Cisco Meraki connection.
  1. Click the Cisco Meraki connection
  2. Click Edit API connection
  3. Enter API Key
  4. Click Save

b. Configurations in Sentinel

  1. In Microsoft sentinel analytical rules should be configured to trigger an incident with risky IP address, URL or Hosts.
  2. Configure the automation rules to trigger the playbooks.

References

Connector

Playbooks

Known Issues and Limitations

  • Need to authorize the api connections after deploying the playbooks.
  • For Block Device Client Playbook, While configuring the rule in Microsoft Sentinel - Device Client MAC needs to be mapped with hostname in Host entity.