Overview
The Meraki Firewall integration enables ThreatAware to collect data from your Meraki dashboard, providing visibility into network security events and device communications.Connection Method: API
Setup Time: 10 minutes
Access Required: Meraki Administrator account
Data collected
The Meraki Firewall integration provides:- Network security events
- Device communications
- Network health indicators
- Firewall rule enforcement
Use cases
Network Security Monitoring
Monitor firewall events and network security across your organisation
Device Communication Tracking
Track device communications and network patterns
Security Event Detection
Identify anomalies and potential security threats
Compliance Reporting
Generate reports for security compliance requirements
Setup instructions
1
Enable API Access in Meraki
Log in to your Meraki Dashboard with administrator credentials.Navigate to your organisation settings:
- Select the appropriate Organisation
- Go to Organisation Settings
- Ensure that Dashboard API access is enabled
2
Generate an API Key
Create an administrator account specifically for ThreatAware API access (recommended):
- Navigate to the Admin profile for an administrator account
- Scroll to the API Access section
- Click Generate new API key
- Copy the API key and save it securely for use in ThreatAware
3
Retrieve Organisation ID
The Organisation ID identifies which Meraki organisation to monitor:
- Ensure you are logged in as the API admin
- Visit the Meraki API Organisations endpoint
- The page displays JSON with all accessible organisations
- Find and copy the ID field for the organisation to monitor
- Save this ID for the next step
4
Enable Hostname Visibility
Ensure hostname visibility is enabled for accurate device identification:
- For each Meraki network to monitor, verify Hostname Visibility is enabled
- Refer to Meraki Hostname Visibility Documentation for detailed instructions
5
Configure in ThreatAware
Add the Meraki Firewall integration to ThreatAware:
- Log in to ThreatAware and navigate to Settings → Integrations
- Search for Meraki Firewall and click Connect
- In the pop-up window, enter:
- Organisation ID: The ID copied in Step 3
- API Key: The key generated in Step 2
- Click Authorize to complete the setup
6
Verify Connection
Confirm the integration is working:
- Check the integration status in ThreatAware shows Active
- Wait 5-10 minutes for initial data synchronization
- Verify firewall events and device data appear in ThreatAware
Required credentials
API Key
API Key
Field Name: Meraki API Key
Type: Password (encrypted)
Description: The API key generated from your Meraki administrator accountThis key provides read-only access to your Meraki dashboard data. Generate it through:
- Your Meraki admin profile > API Access section
- Or create a dedicated admin account for ThreatAware
Organisation ID
Organisation ID
Field Name: Meraki Organisation ID
Type: String
Description: The unique identifier for your Meraki organisationFound by:
- Visiting the Meraki API Organisations endpoint
- Copying the ID value from the JSON response
- Example format:
123456
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings → Integrations in ThreatAware
- Confirm Meraki Firewall shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait 5-10 minutes for initial data sync
- Check for Meraki firewall events in the dashboard
- Verify device network information is populated
-
Test Queries
- Create a test query to filter devices with Meraki data
- Verify network security events appear as expected
Troubleshooting
Invalid API Key Error
Invalid API Key Error
Symptoms: Integration fails with authentication errorSolutions:
- Verify the API key is copied correctly without extra spaces
- Ensure the API key has not expired or been revoked
- Check that Dashboard API access is enabled in Organisation Settings
- Regenerate the API key if needed and update ThreatAware
Organisation ID Not Found
Organisation ID Not Found
Symptoms: Integration fails to find the organisationSolutions:
- Verify the Organisation ID is correct from the API endpoint
- Ensure the API admin has access to this organisation
- Check that the ID format is correct (numeric string)
- Visit the Meraki API Organisations endpoint again to confirm the ID
No Firewall Events Appearing
No Firewall Events Appearing
Symptoms: Integration is active but no firewall data appearsSolutions:
- Verify Hostname Visibility is enabled on Meraki networks
- Check that firewall events are occurring in your Meraki dashboard
- Ensure the organisation ID contains devices with firewall data
- Wait up to 10 minutes for initial data synchronization
- Review network rules to confirm events are being generated
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or frequently disconnectsSolutions:
- Verify your network allows HTTPS (443) outbound to Meraki APIs
- Check that api.meraki.com is accessible from your ThreatAware instance
- Temporarily disable any VPN or proxy and test the connection
- Contact Meraki support if api.meraki.com is blocked
Additional resources
Meraki Dashboard
Access your Meraki dashboard to manage your account and API settings
Meraki API Documentation
Official Meraki API documentation for authentication and endpoints
Hostname Visibility Guide
Instructions for enabling hostname visibility on your Meraki networks
ThreatAware Support
Contact ThreatAware support for integration assistance