Enhancing network visibility and security with insights from Meraki
As a Cisco Meraki customer, you appreciate the vast amount of data you get from your Meraki ecosystem. It addresses many of your network management use cases, including:
- Infrastructure health
- Monitoring device availability
- Monitoring environmental sensor readings
- Network performance analytics
- Top devices by usage and energy
- SD-WAN and gateway statistics
- Advanced operations
- License management and API usage
- Firmware and system updates
- Event monitoring
- Access points
- Cameras
- Switches
- Security appliances
- Log security and threat detections
- Organization security events
- Air Marshal wireless protection
However, the amount of data can be overwhelming and difficult to correlate across locations or with data coming in from other related Cisco software. You might also find it difficult to create custom reporting and provide long-term analytics. Bringing Meraki data into the Splunk platform through the Cisco Meraki Add-on for Splunk provides the observability you need. This article explains how.
How to use Splunk software for this use case
The Cisco Meraki Add-on for Splunk works in the following way:
- The Data Collector pulls data from Meraki APIs at scheduled intervals.
- The Data Processor normalizes and enriches the collected data.
- The Data Forwarder sends the processed data to Splunk via HEC.
- Splunk ingests the data and indexes it for search and analysis.
- The Web UI provides dashboards, reports, and alerts based on the ingested data.
The videos in this article show how, after your Meraki data is flowing into the Splunk platform, you can:
- Customize data collection through scheduled API polling
- Deploy real-time webhooks to meet specific monitoring needs
- Use the Splunk AI Assistant to quickly develop SPL queries to get the information you need
For complete information on installing and configuring the add-on, see the Cisco Meraki Add-on for Splunk documentation, or watch the walkthrough from the Cisco Live talk, Splunk + Meraki Integration for Enhanced Network Visibility and Security.
Customized data collection
This add-on collects rich data via Cisco Meraki REST APIs and provides sample visualizations to help you explore the data. However, the dashboards, panels, and visualizations provided might not meet your needs exactly. This video shows you how to change the queries to create custom dashboards.
Webhooks
You might prefer to get the data you need via webhook, rather than polling APIs. This video shows that setup.
Splunk AI Assistant
If you are new to Splunk software, you probably aren't familiar with Splunk search processing language (SPL). Without that knowledge, you won't be able to customize the dashboards in the add-on to get the monitoring and reporting you need. The Splunk AI Assistant drastically speeds up your time to query proficiency by allowing you to describe what you want to do in natural language. Watch how effective this add-on is in the following demo.
Additional resources
Now that you know how to get more value out of your Meraki environment by using the Splunk platform, watch the full talk from Cisco Live EMEA 2026, Splunk + Meraki Integration for Enhanced Network Visibility and Security. In the talk, you can watch a detailed demo on installing and configuring the Cisco Meraki Add-on for Splunk, as well as see a demo of how the Cisco Enterprise Networking for Splunk Platform add-on can help you correlate Meraki data with other Cisco appliance data.
You might also be interested in the following articles:
- Meraki Documentation: Cisco Meraki Add-on for Splunk
- Splunk Help: Get started with Search

