Skip to main content

Overview

The Meraki Firewall integration enables ThreatAware to collect data from your Meraki dashboard, providing visibility into network security events and device communications.
Connection Method: API Setup Time: 10 minutes Access Required: Meraki Administrator account

Data collected

The Meraki Firewall integration provides:
  • Network security events
  • Device communications
  • Network health indicators
  • Firewall rule enforcement

Use cases

Network Security Monitoring

Monitor firewall events and network security across your organisation

Device Communication Tracking

Track device communications and network patterns

Security Event Detection

Identify anomalies and potential security threats

Compliance Reporting

Generate reports for security compliance requirements

Setup instructions

1

Enable API Access in Meraki

Log in to your Meraki Dashboard with administrator credentials.Navigate to your organisation settings:
  • Select the appropriate Organisation
  • Go to Organisation Settings
  • Ensure that Dashboard API access is enabled
2

Generate an API Key

Create an administrator account specifically for ThreatAware API access (recommended):
  • Navigate to the Admin profile for an administrator account
  • Scroll to the API Access section
  • Click Generate new API key
  • Copy the API key and save it securely for use in ThreatAware
Store this API key securely. Anyone with this key can access your Meraki dashboard data.
3

Retrieve Organisation ID

The Organisation ID identifies which Meraki organisation to monitor:
  • Ensure you are logged in as the API admin
  • Visit the Meraki API Organisations endpoint
  • The page displays JSON with all accessible organisations
  • Find and copy the ID field for the organisation to monitor
  • Save this ID for the next step
4

Enable Hostname Visibility

Ensure hostname visibility is enabled for accurate device identification:
5

Configure in ThreatAware

Add the Meraki Firewall integration to ThreatAware:
  • Log in to ThreatAware and navigate to Settings → Integrations
  • Search for Meraki Firewall and click Connect
  • In the pop-up window, enter:
    • Organisation ID: The ID copied in Step 3
    • API Key: The key generated in Step 2
  • Click Authorize to complete the setup
6

Verify Connection

Confirm the integration is working:
  • Check the integration status in ThreatAware shows Active
  • Wait 5-10 minutes for initial data synchronization
  • Verify firewall events and device data appear in ThreatAware

Required credentials

Field Name: Meraki API Key Type: Password (encrypted) Description: The API key generated from your Meraki administrator accountThis key provides read-only access to your Meraki dashboard data. Generate it through:
  • Your Meraki admin profile > API Access section
  • Or create a dedicated admin account for ThreatAware
Use a dedicated administrator account for ThreatAware API access to maintain security audit trails.
Field Name: Meraki Organisation ID Type: String Description: The unique identifier for your Meraki organisationFound by:

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings → Integrations in ThreatAware
    • Confirm Meraki Firewall shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait 5-10 minutes for initial data sync
    • Check for Meraki firewall events in the dashboard
    • Verify device network information is populated
  3. Test Queries
    • Create a test query to filter devices with Meraki data
    • Verify network security events appear as expected

Troubleshooting

Symptoms: Integration fails with authentication errorSolutions:
  • Verify the API key is copied correctly without extra spaces
  • Ensure the API key has not expired or been revoked
  • Check that Dashboard API access is enabled in Organisation Settings
  • Regenerate the API key if needed and update ThreatAware
Symptoms: Integration fails to find the organisationSolutions:
  • Verify the Organisation ID is correct from the API endpoint
  • Ensure the API admin has access to this organisation
  • Check that the ID format is correct (numeric string)
  • Visit the Meraki API Organisations endpoint again to confirm the ID
Symptoms: Integration is active but no firewall data appearsSolutions:
  • Verify Hostname Visibility is enabled on Meraki networks
  • Check that firewall events are occurring in your Meraki dashboard
  • Ensure the organisation ID contains devices with firewall data
  • Wait up to 10 minutes for initial data synchronization
  • Review network rules to confirm events are being generated
Symptoms: Integration fails to connect or frequently disconnectsSolutions:
  • Verify your network allows HTTPS (443) outbound to Meraki APIs
  • Check that api.meraki.com is accessible from your ThreatAware instance
  • Temporarily disable any VPN or proxy and test the connection
  • Contact Meraki support if api.meraki.com is blocked

Additional resources

Meraki Dashboard

Access your Meraki dashboard to manage your account and API settings

Meraki API Documentation

Official Meraki API documentation for authentication and endpoints

Hostname Visibility Guide

Instructions for enabling hostname visibility on your Meraki networks

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Dedicated Service Account
  • Create a dedicated administrator account specifically for ThreatAware
  • This improves security audit trails and makes it easy to revoke access
  • Document the account in your security policy
API Key Rotation
  • Rotate the API key annually or per your security policy
  • Keep previous keys for a short period during transitions
  • Update ThreatAware immediately with the new key
Monitor API Usage
  • Review Meraki dashboard logs periodically for ThreatAware API calls
  • Set up alerts for failed API authentication attempts
  • Monitor data synchronization to ensure integration health