Azure / Azure-Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.
https://azure.microsoft.com/en-us/services/azure-sentinel/
MIT License
4.37k stars 2.89k forks source link

Update Network Session ASIM parser for Cisco Meraki #10710

Open tduarte14 opened 6 days ago

tduarte14 commented 6 days ago

Added direction field for flows/firewall logType and added extra parsing for deviceAction for the inbound traffic (this one uses 0 for allow and 1 for deny). Based on: https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Server_Overview_and_Configuration

Required items, please complete

Change(s):

tduarte14 commented 3 hours ago

Can someone please update?