Home > Switches > Monitoring and Reporting > Navigating the Event Log

Navigating the Event Log

The Event log can be used to track a number of events occurring across a network.  This article describes how to navigate the Event log and filter out extraneous information for troubleshooting and monitoring purposes.

Using the Event Log

Each Meraki network has its own event log, accessible under Network-wide > Monitor > Event log. In a combined network, click the drop-down menu at the top of the page and select the event log for one of the following options:

  • for security appliances to display information about the MX security appliance in this network.
  • for access points to display information about all MR wireless access points in the network.
  • for switches to display information about all MS switches in the network.
  • for clients to display information about all managed SM clients in the network.

Filtering the Event Log

While the event log provides a thorough timeline of events on the network, it is usually unnecessary to view all events across all devices. The following options are available to filter down the event log as needed:

Filtering by Client or Cisco Meraki Device

Filtering events to a specific client can help troubleshoot individual connectivity issues, including IP addressing and network authentication. Entering the MAC address, hostname, or custom name in the Client field will display only events affecting that client, excluding other client information and device events.

An additional, product-specific field can be used to filter to events relevant to a specific device in the network. This can be helpful when troubleshooting a particular Meraki device on the network, or a client connected directly to a specific device.

Filtering by Date and Time

The Event log shows all events for clients and devices, starting with the most recent event by default. This time frame can be adjusted using the Before field, displaying only events that happened at or before the specified time. 

Note: This time shares the time zone set for the network itself. More information on changing this time zone can be found here.

Filtering by Event Type

Even when filtering by a single device or client, there can be quite a few events. Selecting specific events to display or excluding specific event types can significantly decrease the amount of data to sort through.

Each Meraki product offers a different variety of reported events, as listed below:

MR Access Points

The following types of events will be reported by MR access points:

  • 802.11: Wireless association and disassociations
  • WPA: WPA authentication and deauthentications
  • 802.1x: RADIUS authentication and deauthentications
  • Auth: Splash page authentication
  • AutoRF: Channel scans
  • Dropped: Too many events were generated too quickly, creating an Events Dropped event
  • Status: Wired port information
  • L3 Roaming: Events related to Layer 3 Roaming
  • Air Marshal: Packet floods
  • DFS: Events related to Dynamic Frequency Selection
  • Meraki VPN: VPN tunnel drops and connectivity events

Learn more about Common wireless event log messages.

MX Security Appliance

The following types of events will be reported by MX security appliances:

  • DHCP: DHCP leases and related errors
  • IP Conflicts: Detected IP conflicts on the network
  • Auth: Splash page authentication
  • Client Status: Client connectivity
  • Filtering: Content filtering blocks
  • Meraki VPN: AutoVPN connectivity events
  • Non-Meraki / Client VPN: Non-Meraki and Client VPN connectivity events 
  • Dropped: Too many events were generated too quickly, creating an Events Dropped event
  • Intrusion Detection: IDS (Advanced Security only)
  • Cellular: 3G/4G connectivity
  • VRRP: Warm spare transition
  • Status: Device status events
  • OSPF: Events related to OSPF routing

MS Switch

The following types of events will be reported by MS switches:

  • 802.1x: RADIUS authentication and deauthentications
  • DHCP: DHCP leases and related errors
  • Switch port: Port status and STP information
  • Dropped: Too many events were generated too quickly, creating an Events Dropped event
  • OSPF: Events related to OSPF routing
  • VRRP: Warm spare transition

Learn more about MS event log entries and definitions

SM Clients

The following types of events will be reported by managed SM clients:

  • Live Tools: Recent usage of live tools on client devices
  • MDM: Detailed information about changes in device management
  • Remote Desktop: Usage of the remote desktop tool
Last modified



This page has no classifications.

Explore the Product

Click to Learn More

Article ID

ID: 2322

Explore Meraki

You can find out more about Cisco Meraki on our main site, including information on products, contacting sales and finding a vendor.

Explore Meraki

Contact Support

Most questions can be answered by reviewing our documentation, but if you need more help, Cisco Meraki Support is ready to work with you.

Open a Case

Ask the Community

In the Meraki Community, you can keep track of the latest announcements, find answers provided by fellow Meraki users and ask questions of your own.

Visit the Community