---
title: "network.meraki"
canonical: "https://docs.devo.com/space/latest/94664729/network.meraki"
format: markdown
---
> Macro (toc)

## Introduction

The tags beginning with `network.meraki` identify events generated by [Cisco Meraki Network Security](https://meraki.cisco.com/products/security-sd-wan/) products.

## Valid tags and data tables

<span style="color: #282828">The full tag must have </span>at least 3<span style="color: #282828"> levels. The first two are fixed as</span>** **`network.meraki`<span style="color: #282828">. The third level identifies the type of events sent. The fourth, fifth, and sixth levels indicate the event subtypes and are used in the</span><span style="color: #282828">** **</span>`network.meraki.api`<span style="color: #282828"> tags.</span>

These are the valid tags and corresponding data tables that will receive the parsers' data:

| **Product / Service** | **Tags** | **Data tables** |
| --- | --- | --- |
| Cisco Meraki | `network.meraki.ids-alerts` | `network.meraki` |
| `network.meraki.events` |
| `network.meraki.flows` |
| `network.meraki.urls` |
| `network.meraki.airmarshal_events` | `network.meraki.airmarshal_events` |
| `network.meraki.api.events.1.json` | `network.meraki.api.events` |
| `network.meraki.api.security_events.1.json` | `network.meraki.api.security_events` |
| `network.meraki.events` | `network.meraki.events` |
| `network.meraki.firewall` | `network.meraki.firewall` |
| `network.meraki.flows` | `network.meraki.flows` |
| `network.meraki.ids-alerts` | `network.meraki.idsAlerts` |
| `network.meraki.ip_flow_end` | `network.meraki.ip_flow_end` |
| `network.meraki.ip_flow_start` | `network.meraki.ip_flow_start` |
| `network.meraki.l7_firewall` | `network.meraki.l7_firewall` |
| `network.meraki.security_event` | `network.meraki.security_event` |
| `network.meraki.switch` | `network.meraki.switch` |
| `network.meraki.urls` | `network.meraki.urls` |
| `network.meraki.vpn_firewall` | `network.meraki.vpn_firewall` |

For more information, read more [ About Devo tags](https://docs.devo.com/space/latest/95126204).

## <span style="color: #282828">How is the data sent to Devo?</span>

<span style="color: #000000">To send logs to the </span>`network.meraki.api.events`<span style="color: #000000"> and </span>`network.meraki.api.security_events`** **<span style="color: #000000">tables, Devo provides a collector that you can download and use to send the required events to your Devo domain. You can learn how to use it in </span><span style="color: #000000">[Cisco Meraki collector](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94655804)</span><span style="color: #000000">.</span>

For the rest of tables, you must define a specific relay rule to send the events to Devo properly. For events generated by **Meraki MS Switches**, use [rule 1](#rule1); for events generated by a **Meraki MX Security Appliance** or a **Meraki MR Access Point**, you must use [rule 2](#rule2). For more information about event types and log samples, [check this article](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Event_Types_and_Log_Samples).

### > Macro (anchor)

Rule 1 - Switch events  


![image-20250424-195156.png](media://af09e0cd-693a-40e7-9d37-9762d5c2a1e3)

Create a rule with the following values for logs generated by **Meraki MS Switch** devices (the port number can be any free port on your relay):

- **Target tag** → `network.meraki.switch`
- Check the **Stop processing** and **Sent without syslog tag** checkboxes

### > Macro (anchor)

Rule 2 - Other events

Use this rule for events generated by a **Meraki MX Security Appliance** or a **Meraki MR Access Point**. If you configure this rule, the relay will apply a tag that begins with** **`network.meraki`** **when the source conditions are met. A regular expression in the **Source data** field describes the format of the event data and identifies the event type as a capturing group. This capturing group is extracted from the event and used to create the third level of the tag.

> ⚠️ You don't need to apply this rule if you are sending Switch events only. In case you need to apply both rules, you must define the Switch rule first.

Define the rule using the following values (the port number can be any free port on your relay):

- **Source data** → `[^ ]+ [^ ]+ ([^ ]+) .*`
- **Target tag **→ `network.meraki.\\D1`
- **Target message** → `\\D0`
- Check the **Stop processing** and **Sent without syslog tag** checkboxes

### Configure log forwarding from Meraki

There are a couple of ways to configure the output to a Syslog Server in Meraki. Consult the [vendor documentation](https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Syslog_Server_Overview_and_Configuration#Configuring_a_Syslog_Server) for instructions. 

If your environment has multiple MX devices using a site-to-site VPN, and the logging is done to a Devo Relay outside the VPN, be sure that you create a site-to-site firewall rule that will permit outbound traffic to the relay. Consult the [vendor documentation](https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Firewall_Settings) for instructions for creating an outbound traffic rule. In this rule, the Source should be the Internet port 1 address of the sending machine. The Destination should be the IP address of the Devo Relay and the Dst Port should be the relay port specified in the Devo Relay rule.

### Sending Layer 7 firewall data to Devo

Layer 7 data may be sent through a Devo relay using this example relay rule:

```
         Source message: 
            Source data: 
             Source tag: 
             Target tag: network.meraki.l7_firewall
Sent without syslog tag: false
```

### Table structure

These are the fields displayed in these tables:

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> - [network.meraki](#tag1)
> - [network.meraki.airmarshal_events](#tag2)
> - [network.meraki.api.events](#tag3)
> - [network.meraki.api.security_events](#tag4)
> - [network.meraki.events](#tag5)
> 
> ### > Macro (anchor)
> 
> network.meraki
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *dvc_host* | `str` | *vhost* |  |
> | *type* | `str` | *vtype* |  |
> | *serverdate* | `timestamp` | * * |  |
> | *dvc_name* | `str` | * * |  |
> | *logtype* | `str` | * * |  |
> | *hostchain* | `str` | * * | **✓** |
> | *tag* | `str` | * * | **✓** |
> | *rawMessage* | `str` | *rawSource* | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.airmarshal_events
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *serverdate* | `timestamp` |  |  |
> | *dvc_host* | `str` | *vhost* |  |
> | *dvc_name* | `str` |  |  |
> | *type* | `str` |  |  |
> | *ssid* | `str` |  |  |
> | *vap* | `str` |  |  |
> | *bssid* | `str` |  |  |
> | *src* | `str` |  |  |
> | *dst* | `str` |  |  |
> | *wired_mac* | `str` |  |  |
> | *vlan_id* | `str` |  |  |
> | *channel* | `str` |  |  |
> | *rssi* | `str` |  |  |
> | *fc_type* | `str` |  |  |
> | *fc_subtype* | `str` |  |  |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> | *rawMessage* | `str` | *rawSource* | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.api.events
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *occurredAt* | `timestamp` |  |
> | *networkId* | `str` |  |
> | *type* | `str` |  |
> | *description* | `str` |  |
> | *clientId* | `str` |  |
> | *clientDescription* | `str` |  |
> | *deviceSerial* | `str` |  |
> | *deviceName* | `str` |  |
> | *ssidNumber* | `int8` |  |
> | *ssidName* | `str` |  |
> | *eventDataRadio* | `str` |  |
> | *eventDataVap* | `str` |  |
> | *eventDataClientMac* | `str` |  |
> | *eventDataClientIp* | `str` |  |
> | *eventDataChannel* | `str` |  |
> | *eventDataRssi* | `str` |  |
> | *eventDataAid* | `str` |  |
> | *eventDataRaw* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.api.security_events
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *hostname* | `str` |  |
> | *ts* | `timestamp` |  |
> | *eventType* | `str` |  |
> | *clientName* | `str` |  |
> | *clientMac* | `str` |  |
> | *clientIp* | `str` |  |
> | *srcIp* | `str` |  |
> | *srcPort* | `str` |  |
> | *destIp* | `str` |  |
> | *destPort* | `str` |  |
> | *protocol* | `str` |  |
> | *uri* | `str` |  |
> | *canonicalName* | `str` |  |
> | *destinationPort* | `int8` |  |
> | *fileHash* | `str` |  |
> | *fileType* | `str` |  |
> | *fileSizeBytes* | `int8` |  |
> | *disposition* | `str` |  |
> | *action* | `str` |  |
> | *deviceMac* | `str` |  |
> | *priority* | `str` |  |
> | *classification* | `str` |  |
> | *blocked* | `bool` |  |
> | *message* | `str` |  |
> | *signature* | `str` |  |
> | *sigSource* | `str` |  |
> | *ruleId* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.events
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |  |
> | *serverdate* | `timestamp` |  |  |  |
> | *dvc_host* | `str` |  | *vhost* |  |
> | *dvc_name* | `str` |  |  |  |
> | *type* | `str` |  |  |  |
> | *vpn_type* | `str` |  |  |  |
> | *peer_contact* | `str` |  |  |  |
> | *peer_ident* | `str` |  |  |  |
> | *connectivity* | `bool` |  |  |  |
> | *radio* | `str` |  |  |  |
> | *vap* | `str` |  |  |  |
> | *process_name* | `str` |  |  |  |
> | *pid* | `str` |  |  |  |
> | *client_ip* | `ip4` |  |  |  |
> | *client_internal_ip* | `ip4` |  |  |  |
> | *client_mac* | `str` |  |  |  |
> | *channel* | `str` |  |  |  |
> | *active* | `str` |  |  |  |
> | *rssi* | `str` |  |  |  |
> | *skip* | `str` |  |  |  |
> | *clients* | `str` |  |  |  |
> | *mesh_in* | `str` |  |  |  |
> | *mesh_out* | `str` |  |  |  |
> | *duration* | `float8` |  |  |  |
> | *auth_neg_failed* | `str` |  |  |  |
> | *auth_neg_duration* | `float8` |  |  |  |
> | *last_auth_ago* | `float8` |  |  |  |
> | *is_wpa* | `str` |  |  |  |
> | *full_conn* | `float8` |  |  |  |
> | *ip_resp* | `float8` |  |  |  |
> | *ip_src* | `ip4` |  |  |  |
> | *arp_resp* | `float8` |  |  |  |
> | *arp_src* | `ip4` |  |  |  |
> | *dns_server* | `ip4` |  |  |  |
> | *dns_req_rtt* | `float8` |  |  |  |
> | *dns_resp* | `float8` |  |  |  |
> | *original_server_ip* | `ip4` |  |  |  |
> | *original_server_mac* | `str` |  |  |  |
> | *server_ip* | `ip4` |  |  |  |
> | *server_port* | `str` |  |  |  |
> | *server_mac* | `str` |  |  |  |
> | *dhcp_failed* | `str` |  |  |  |
> | *reason* | `str` |  |  |  |
> | *instigator* | `str` |  |  |  |
> | *device_ip* | `str` |  |  |  |
> | *http_resp* | `float8` |  |  |  |
> | *load* | `str` |  |  |  |
> | *best_ap* | `ip4` |  |  |  |
> | *best_ap_load* | `str` |  |  |  |
> | *best_ap_rssi* | `str` |  |  |  |
> | *aid* | `str` |  |  |  |
> | *spi* | `str` |  |  |  |
> | *spi_inbound* | `str` |  |  |  |
> | *spi_outbound* | `str` |  |  |  |
> | *inbound_bytes* | `int8` |  |  |  |
> | *outbound_bytes* | `int8` |  |  |  |
> | *proto_id* | `str` |  |  |  |
> | *source_client_assigned_vlan* | `int4` |  |  |  |
> | *last_illegal_ip_mapped_vlan_id* | `int4` |  |  |  |
> | *client_total_illegal_packets* | `int8` |  |  |  |
> | *all_total_illegal_packets* | `int8` |  |  |  |
> | *last_reported_total* | `int8` |  |  |  |
> | *lease_ip* | `ip4` |  |  |  |
> | *router_ip* | `ip4` |  |  |  |
> | *subnet* | `ip4` |  |  |  |
> | *dns1* | `ip4` |  |  |  |
> | *dns2* | `ip4` |  |  |  |
> | *vpn_name* | `str` |  |  |  |
> | *vpn_id* | `str` |  |  |  |
> | *local_subnet* | `str` |  |  |  |
> | *local_tunnel* | `str` |  |  |  |
> | *remote_subnet* | `str` |  |  |  |
> | *remote_tunnel* | `str` |  |  |  |
> | *user_id* | `str` |  |  |  |
> | *local_ip* | `str` |  |  |  |
> | *local_ip4* | `ip4` | ```
> ip4(local_ip)
> ``` | *local_ip* |  |
> | *url* | `str` |  |  |  |
> | *rawMessage* | `str` |  |  | **✓** |
> | *hostchain* | `str` |  |  | **✓** |
> | *tag* | `str` |  |  | **✓** |
> 
> > Macro (rw-tab)
> 
> - [network.meraki.firewall](#tag6)
> - [network.meraki.flows](#tag7)
> - [network.meraki.idsAlerts](#tag8)
> - [network.meraki.ip_flow_end](#tag9)
> - [network.meraki.ip_flow_start](#tag10)
> 
> ### > Macro (anchor)
> 
> network.meraki.firewall
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *hostname* | `str` |  |  |
> | *server_date* | `timestamp` |  |  |
> | *dvc_host* | `str` | *vhost* |  |
> | *dvc_name* | `str` |  |  |
> | *log_type* | `str` |  |  |
> | *source_ip* | `ip4` |  |  |
> | *destination_ip* | `ip4` |  |  |
> | *mac* | `str` |  |  |
> | *protocol* | `str` |  |  |
> | *srcPort* | `int4` |  |  |
> | *dstPort* | `int4` |  |  |
> | *icmpType_1* | `str` |  |  |
> | *pattern_1* | `str` |  |  |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> | *rawSource* | `str` |  | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.flows
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  | * * |  |
> | *serverdate* | `timestamp` |  | * * |  |
> | *dvc_host* | `str` |  | *vhost* |  |
> | *dvc_name* | `str` |  | * * |  |
> | *action* | `str` | ```
> (action_1 != null) ? action_1 : (startswith(pattern, "1")) ? "deny" : (startswith(pattern, "0")) ? "allow" : (pattern ->> "allow") ? "allow" : (pattern ->> "deny") ? "deny" : null("")
> ``` | *action_1*<br>*pattern* |  |
> | *logtype* | `str` |  | * * |  |
> | *srcIp* | `ip4` |  | * * |  |
> | *srcPort* | `int4` |  | * * |  |
> | *dstIp* | `ip4` |  | * * |  |
> | *dstPort* | `int4` |  | * * |  |
> | *proto* | `str` |  | * * |  |
> | *mac* | `str` |  | * * |  |
> | *icmpType* | `str` | ```
> (icmpType_1 -> 'pattern: ') ? split(icmpType_1, 'pattern:', 0) : icmpType_1
> ``` | *icmpType_1* |  |
> | *pattern* | `str` | ```
> (icmpType_1 -> 'pattern: ') ? split(icmpType_1, 'pattern: ', 1) : pattern_1
> ``` | *pattern_1*<br>*icmpType_1* |  |
> | *translated_src_ip* | `ip4` |  | * * |  |
> | *translated_dst_ip* | `ip4` |  | * * |  |
> | *translated_port* | `int4` |  | * * |  |
> | *hostchain* | `str` |  | * * | **✓** |
> | *tag* | `str` |  | * * | **✓** |
> | *rawMessage* | `str` |  | *rawSource* | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.idsAlerts
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *serverdate* | `timestamp` |  |  |
> | *dvc_host* | `str` | *vhost* |  |
> | *dvc_name* | `str` |  |  |
> | *srcIp* | `ip4` |  |  |
> | *srcPort* | `int4` |  |  |
> | *dstIp* | `ip4` |  |  |
> | *dstPort* | `int4` |  |  |
> | *signature* | `str` |  |  |
> | *priority* | `int4` |  |  |
> | *tstamp* | `timestamp` |  |  |
> | *dhost* | `str` |  |  |
> | *direction* | `str` |  |  |
> | *proto* | `str` |  |  |
> | *message* | `str` |  |  |
> | *unknown* | `str` |  |  |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> | *rawMessage* | `str` | *rawSource* | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.ip_flow_end
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  | * * |  |
> | *serverdate* | `timestamp` |  | * * |  |
> | *dvc_host* | `str` |  | *vhost* |  |
> | *dvc_name* | `str` |  | * * |  |
> | *action* | `str` | ```
> (action_1 != null) ? action_1 : (startswith(pattern, "1")) ? "deny" : (startswith(pattern, "0")) ? "allow" : (pattern ->> "allow") ? "allow" : (pattern ->> "deny") ? "deny" : null("")
> ``` | *action_1*<br>*pattern* |  |
> | *logtype* | `str` |  | * * |  |
> | *srcIp* | `ip4` |  | * * |  |
> | *srcPort* | `int4` |  | * * |  |
> | *dstIp* | `ip4` |  | * * |  |
> | *dstPort* | `int4` |  | * * |  |
> | *proto* | `str` |  | * * |  |
> | *mac* | `str` |  | * * |  |
> | *icmpType* | `str` | ```
> (icmpType_1 -> 'pattern: ') ? split(icmpType_1, 'pattern:', 0) : icmpType_1
> ``` | *icmpType_1* |  |
> | *pattern* | `str` | ```
> (icmpType_1 -> 'pattern: ') ? split(icmpType_1, 'pattern: ', 1) : pattern_1
> ``` | *pattern_1*<br>*icmpType_1* |  |
> | *translated_src_ip* | `ip4` |  | * * |  |
> | *translated_dst_ip* | `ip4` |  | * * |  |
> | *translated_port* | `int4` |  | * * |  |
> | *hostchain* | `str` |  | * * | **✓** |
> | *tag* | `str` |  | * * | **✓** |
> | *rawMessage* | `str` |  | *rawSource* | **✓** |
> 
> ### > Macro (anchor)
> 
> network.meraki.ip_flow_start
> 
> | **Field** | **Type** | **Field transformation** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  | * * |  |
> | *serverdate* | `timestamp` |  | * * |  |
> | *dvc_host* | `str` |  | *vhost* |  |
> | *dvc_name* | `str` |  | * * |  |
> | *action* | `str` | ```
> (action_1 != null) ? action_1 : (startswith(pattern, "1")) ? "deny" : (startswith(pattern, "0")) ? "allow" : (pattern ->> "allow") ? "allow" : (pattern ->> "deny") ? "deny" : null("")
> ``` | *action_1*<br>*pattern* |  |
> | *logtype* | `str` |  | * * |  |
> | *srcIp* | `ip4` |  | * * |  |
> | *srcPort* | `int4` |  | * * |  |
> | *dstIp* | `ip4` |  | * * |  |
> | *dstPort* | `int4` |  | * * |  |
> | *proto* | `str` |  | * * |  |
> | *mac* | `str` |  | * * |  |
> | *icmpType* | `str` | ```
> (icmpType_1 -> 'pattern: ') ? split(icmpType_1, 'pattern:', 0) : icmpType_1
> ``` | *icmpType_1* |  |
> | *pattern* | `str` | ```
> (icmpType_1 -> 'pattern: ') ? split(icmpType_1, 'pattern: ', 1) : pattern_1
> ``` | *pattern_1*<br>*icmpType_1* |  |
> | *translated_src_ip* | `ip4` |  | * * |  |
> | *translated_dst_ip* | `ip4` |  | * * |  |
> | *translated_port* | `int4` |  | * * |  |
> | *hostchain* | `str` |  | * * | **✓** |
> | *tag* | `str` |  | * * | **✓** |
> | *rawMessage* | `str` |  | *rawSource* | **✓** |
> 
> > Macro (rw-tab)
> 
> - [network.meraki.l7_firewall](#tag11)
> - [network.meraki.security_event](#tag12)
> - [network.meraki.switch](#tag13)
> - [network.meraki.urls](#tag14)
> - [network.meraki.vpn_firewall](#tag15)
> 
> ### network.meraki.l7_firewall
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *hostname* | `str` |  |  |
> | *epoch_time* | `str` |  |  |
> | *host* | `str` | *vhost* |  |
> | *log_type* | `str` |  |  |
> | *source_ip* | `ip4` |  |  |
> | *destination_ip* | `ip4` |  |  |
> | *protocol* | `str` |  |  |
> | *sport* | `str` |  |  |
> | *dport* | `str` |  |  |
> | *decision* | `str` |  |  |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> | *rawMessage* | `str` |  | **✓** |
> 
> ### network.meraki.security_event
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *hostname* | `str` |  |  |
> | *host* | `str` | vhost |  |
> | *serverdate* | `timestamp` |  |  |
> | *dvc_name* | `str` |  |  |
> | *logtype* | `str` |  |  |
> | *subtype* | `str` |  |  |
> | *url* | `str` |  |  |
> | *src_ip* | `ip4` |  |  |
> | *src_port* | `str` |  |  |
> | *dst_ip* | `ip4` |  |  |
> | *dst_port* | `str` |  |  |
> | *mac* | `str` |  |  |
> | *name* | `str` |  |  |
> | *sha256* | `str` |  |  |
> | *disposition* | `str` |  |  |
> | *action* | `str` |  |  |
> | *hostchain* | `str` |  | **v** |
> | *tag* | `str` |  | **✓** |
> | *rawMessage* | `str` |  |  |
> 
> ### network.meraki.switch
> 
> | **Field** | **Type** | ***Extra***** fields** |
> | --- | --- | --- |
> | *eventdate* | `timestamp` |  |
> | *serverdate* | `timestamp` |  |
> | *dvc_name* | `str` |  |
> | *dvc_ip* | `str` |  |
> | *type* | `str` |  |
> | *port* | `str` |  |
> | *identity* | `str` |  |
> | *resp* | `str` |  |
> | *rtt* | `str` |  |
> | *message* | `str` |  |
> | *hostchain* | `str` | **✓** |
> | *tag* | `str` | **✓** |
> | *rawMessage* | `str` |  |
> 
> ### network.meraki.urls
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *serverdate* | `timestamp` |  |  |
> | *dvc_host* | `str` | *vhost* |  |
> | *dvc_name* | `str` | * * |  |
> | *srcIp* | `ip4` | * * |  |
> | *srcPort* | `int4` | * * |  |
> | *dstIp* | `ip4` | * * |  |
> | *dstPort* | `int4` | * * |  |
> | *mac* | `str` | * * |  |
> | *method* | `str` | * * |  |
> | *url* | `str` | * * |  |
> | *user_agent* | `str` | * * |  |
> | *hostchain* | `str` | * * | **✓** |
> | *tag* | `str` | * * | **✓** |
> | *rawMessage* | `str` | *rawSource* | **✓** |
> 
> ### network.meraki.vpn_firewall
> 
> | **Field** | **Type** | **Source field name** | ***Extra***** fields** |
> | --- | --- | --- | --- |
> | *eventdate* | `timestamp` |  |  |
> | *hostname* | `str` |  |  |
> | *server_date* | `timestamp` |  |  |
> | *dvc_host* | `str` | *vhost* |  |
> | *dvc_name* | `str` |  |  |
> | *log_type* | `str` |  |  |
> | *source_ip* | `ip4` |  |  |
> | *destination_ip* | `ip4` |  |  |
> | *mac* | `str` |  |  |
> | *protocol* | `str` |  |  |
> | *srcPort* | `int4` |  |  |
> | *dstPort* | `int4` |  |  |
> | *icmpType_1* | `str` |  |  |
> | *pattern_1* | `str` |  |  |
> | *hostchain* | `str` |  | **✓** |
> | *tag* | `str` |  | **✓** |
> | *rawSource* | `str` |  |  |