Skip to content

Lookups for the Splunk Add-on for Cisco Meraki

The Splunk Add-on for Cisco Meraki contains the following lookups. The lookup files map fields from Cisco Meraki logs to CIM-compliant values in the Splunk platform. The lookup files are located in $SPLUNK_HOME/etc/apps/Splunk_TA_cisco_meraki/lookups.

Filename Description
cisco_meraki_accesspoints_action_lookup.csv Maps meraki_event_type to action
cisco_meraki_accesspoints_change_type_object_object_category_result_lookup.csv Maps meraki_event_type to object,object_category,result and change_type
cisco_meraki_accesspoints_object_attrs_lookup.csv Maps meraki_event_type to object_attrs
cisco_meraki_cameras_lookup.csv Maps meraki_event_type to action,object_category,change_type and result
cisco_meraki_organizationsecurity_lookup.csv Maps priority to severity
cisco_meraki_securityappliances_action_lookup.csv Maps meraki_event_type to action
cisco_meraki_securityappliances_change_type_result_lookup.csv Maps meraki_event_type to change_type and result
cisco_meraki_securityappliances_object_object_category_lookup.csv Maps meraki_event_type to object and object_category
cisco_meraki_switches_action_lookup.csv Maps meraki_event_type to action
cisco_meraki_switches_change_type_object_lookup.csv Maps meraki_event_type to change_type and object
cisco_meraki_switches_result_lookup.csv Maps meraki_event_type to result