Integrating Cisco Meraki with Zscaler MDR provides a robust security posture by combining cloud-managed networking with advanced threat detection and response capabilities. This integration enables organizations to efficiently monitor network activity, identify potential threats, and accelerate incident response times. To integrate Cisco Meraki with Zscaler MDR, follow the procedure below from beginning to end.
Prerequisite
You will need the Threat Protection option in Meraki, which requires the Advanced Security Edition Licensing within the The security/SD-WAN appliance product line (MX) offering.
Step 1: Zscaler MDR–Create your Zscaler MDR-provided URL
Create a Zscaler MDR provided-URL to send Cisco Meraki alerts for ingestion.
In the Zscaler MDR portal, click Integrations and See all integrations.
.png?sv=2026-02-06&spr=https&st=2026-09-09T23%3A58%3A22Z&se=2026-09-10T00%3A09%3A22Z&sr=c&sp=r&sig=yGoN7bM95Ccr6REZX3WhK2TsXte9%2FJ5IUGpu83DMvS4%3D)
Type and select Cisco Meraki.

Click Configure.
Enter a Name for your external alert source.
Select a Display Category.
Under the Ingest Format/Method dropdown, select Meraki via HTTP. This is the preferred ingest method and generates the best data for investigation and correlation. Please do not use the other available ingest methods.
Click Save Configuration.
Click Activate it to begin processing alerts. This will generate the URL you will use to send Cisco Meraki alerts to.
Note: You may need to refresh the page for the URL to appear.

Copy and save the Zscaler MDR-provided URL. You’ll use this URL in a later step.

Step 2: Cisco Meraki–Enter your Zscaler MDR-provided URL
Adjust your Cisco Meraki alert settings to send generated alerts to your Zscaler MDR-provided URL.
From your Cisco Meraki homepage, click Network-wide, and then click Alerts.
.png?sv=2026-02-06&spr=https&st=2026-09-09T23%3A58%3A22Z&se=2026-09-10T00%3A09%3A22Z&sr=c&sp=r&sig=yGoN7bM95Ccr6REZX3WhK2TsXte9%2FJ5IUGpu83DMvS4%3D)
From the Network-wide section, select A rogue AP is detected.
From the Security appliance section, select Malware is blocked.
From the Security appliance section, select Malware is downloaded.
Note: Other alert types are allowed but not required.
.png?sv=2026-02-06&spr=https&st=2026-09-09T23%3A58%3A22Z&se=2026-09-10T00%3A09%3A22Z&sr=c&sp=r&sig=yGoN7bM95Ccr6REZX3WhK2TsXte9%2FJ5IUGpu83DMvS4%3D)
Scroll down to the Webhooks section, and then click Add an HTTPS receiver.
Enter Zscaler MDR in the name field.
Enter the URL from Step 1.10.
Delete the text in the shared secret field.
From the Payload template dropdown select Meraki.
Assign the Alert to the new webhook per Cisco Meraki’s instructions.
Click Send test webhook.
.png?sv=2026-02-06&spr=https&st=2026-09-09T23%3A58%3A22Z&se=2026-09-10T00%3A09%3A22Z&sr=c&sp=r&sig=yGoN7bM95Ccr6REZX3WhK2TsXte9%2FJ5IUGpu83DMvS4%3D)
Click Save.