Enterprise Security forUniFi Networks
Purpose-built SIEM that integrates natively with every UniFi product. Monitor, detect, and respond to threats across your entire ecosystem.
Native UniFi Integration
Deep integration with every UniFi product for comprehensive visibility.
UniFi Network
Real-time monitoring of network events: IDS/IPS alerts, firewall drops, DHCP and wireless activity, WAN failover and controller changes — each handled by a dedicated parser.
- Syslog & CEF ingestion
- Severity taken from the syslog priority
- Structured 5-tuple from firewall and IDS logs
- Per-device inventory, auto-discovered
UniFi Protect
Smart-detection pipeline activity arrives over syslog. Full detection events come from the Protect Integration API or a signed webhook, once your console permits inbound access.
- Protect Integration API polling
- HMAC-signed webhook receiver
- Detections correlated by event ID
- Reachability preflight with a clear verdict
UniFi Access
Physical access control monitoring for doors, credentials and entry attempts, configured per tenant with its own API key.
- Door and credential events
- Tamper and forced entry raised as security
- Per-tenant API key, encrypted at rest
- Handles every Access response envelope
UniFi Talk
RoadmapOn the roadmap. Talk events are not yet parsed — we would rather tell you that than list a feature you cannot use today.
- Planned: call detail records
- Planned: SIP event logging
Powerful Capabilities
Everything you need to detect, investigate, and respond to security threats.
Detection Engine
Powerful YAML-based rule engine with support for complex conditions, aggregation, and correlation across multiple event sources.
- YAML rule definitions
- Regex pattern matching
- Field aggregation (count events over time)
- Multi-condition logic
- Severity classification
- Automatic alert generation
Multi-Channel Alerting
Get notified instantly through your preferred channels when security events occur.
- Email notifications
- Slack integration
- Discord webhooks
- PagerDuty escalation
- Custom webhook delivery
- Alert deduplication
AI-Powered Analysis
Ask Claude or GPT-5 to explain any event in plain English — what happened, why it matters, and what to do about it. Choose the provider and model per instance and bring your own key.
- Natural language explanations
- Threat context analysis
- Remediation suggestions
- Pattern recognition
- Cached insights for speed
- Configurable prompts
Threat Intelligence
Enrich events with external threat data to identify known malicious actors.
- GeoIP location lookup
- AbuseIPDB reputation
- VirusTotal integration
- ASN information
- Malicious IP blocking
- Intelligent caching
Active Response
Automatically respond to threats by taking action directly on your UniFi infrastructure.
- Client blocking/quarantine
- VLAN reassignment
- Access credential disable
- Rate limiting
- Auto-revert with timers
- Approval workflows
Elasticsearch Storage
Scalable, searchable storage for all your security events with powerful querying capabilities.
- Full-text search
- Complex aggregations
- Time-based retention
- Index lifecycle management
- High availability support
- Custom dashboards
Traffic Analytics (NetFlow / IPFIX)
See exactly what your network is doing. Ingests NetFlow v5, v9 and IPFIX and keeps the detail most collectors discard — switch port, MAC, VLAN, DSCP and BGP AS alongside the 5-tuple.
- NetFlow v5, v9, and IPFIX (v10)
- 60s tumbling-window aggregation
- Top talkers by source, destination, or pair
- Protocol breakdown (TCP/UDP/ICMP/etc.)
- Sortable flow table: bytes, packets, time
- Per-device drill-down and filtering
Network Event Viewer
Separate operational events from security events. Troubleshoot flapping ports, AP radar hits, WAN failovers, and controller provisioning without wading through IDS alerts.
- Link up / down, port flaps, PoE state
- AP radio: DFS radar, channel switch, CAC
- WAN / VPN tunnel state (pppd, IPSec, OpenVPN)
- Controller lifecycle: adopt, provision, upgrade
- Dedicated Network Events page
- Per-device event stream
SNMP Trap Receiver
Listen for v1 and v2c SNMP traps from UniFi switches and gateways. Well-known OIDs are mapped to human-readable names and severity levels.
- SNMPv1 and SNMPv2c / INFORM
- Well-known trap OID mapping (linkUp, authFailure, etc.)
- Optional community-string filtering
- Enterprise-specific OID pass-through
- Full varbind capture in raw event
- Mirrors into the Network Event feed
Structured UniFi Syslog Parsing
Instead of generic keyword matching, dedicated parsers extract the structured fields you need for hunting, correlation, and reporting.
- iptables firewall: 5-tuple, rule name, action
- Suricata IDS: signature ID, classification, priority
- hostapd wireless: STA MAC, association state
- dnsmasq DHCP: IP, MAC, hostname
- Linux auth: SSH, PAM, login success/failure
- Controller: device adoption, provision, upgrade
Multi-Tenant Admin Center
Run Sentinel for multiple clients from a single host. Every client gets their own isolated instance — data, rules, users, and alerts — with automated provisioning end-to-end.
- One-click client instance provisioning
- Automatic subdomain + DNS A record (GoDaddy API)
- Wildcard SSL covering every instance
- Super-admin SSO across all instances
- Per-client resource limits and port allocation
- Centralized rolling upgrades
Per-Tenant Ingest Isolation
Each client gets their own ports for syslog, NetFlow and SNMP, restricted at the firewall to the source addresses you nominate. The destination port alone decides which instance receives a packet.
- Dedicated port per protocol, per tenant
- Source-IP allow-listing enforced in iptables
- No shared collector, no cross-tenant mixing
- Ports listed in the Admin Center — no guessing
- Set at creation, changeable later without data loss
- Unrecognised senders dropped before ingestion
Credential Delivery
Every instance is provisioned with its own admin account. The password is encrypted at rest and can be emailed to the client with all of their ingest endpoints in one message.
- Unique 20-character password per instance
- AES-256-GCM encrypted at rest
- Welcome email lists every allocated port
- Reveal and send both write an audit entry
- Resend to any address without retyping it
- Machine secrets deliberately kept out of email
Backups & Retention
Your event history is the product, so it is snapshotted nightly and aged out on a schedule rather than growing until the disk fills.
- Nightly Elasticsearch snapshots
- Index lifecycle policy applied to every tenant
- Warm tier at 7 days, deletion at 90
- Inherited automatically by new instances
- Tenant indices removed cleanly on deletion
- Retention window configurable per plan
Noise Suppression
A flapping port or a chatty daemon can emit the same line thousands of times an hour. Repeats are collapsed into a single event with a count, so real signal stays visible.
- Identical events collapsed with a repeat count
- Numeric noise normalised before comparison
- Original message always preserved
- Alert rules see the aggregate, not the flood
- Storage and query cost cut substantially
- No configuration required
Device Inventory
Auto-discovered list of every device sending events. Click a device for its full event stream, or filter by device in the Network Events view.
- Derived from event ingestion — no config
- Last-seen and event-count per device
- Device name, MAC, type, site
- Per-device event drill-down endpoint
- 30-day default look-back (configurable)
- Surface-area for operational troubleshooting
Product, not promises
See exactly what your network is telling you.
Three of the views you'll live in: full-fidelity traffic analytics, operational events separated from security noise, and the multi-tenant Admin Center.
Flows
NetFlow v5 / v9 / IPFIX · aggregated by 5-tuple over a 60s window
| Time | Source | Destination | Proto | Flags | VLAN / If | Bytes | Pkts |
|---|---|---|---|---|---|---|---|
| 14:22:07 | 192.0.2.41:51344 workstation-04.lan 8c:30:66:62:67:54 | 198.51.100.9:443 edge.cdn.example.net AS15169 | TCP | PADSCP46 | vlan 30 if 7→9 | 3.3 KB | 12 |
| 14:22:05 | 192.0.2.118:61708 ap-lobby.lan f4:92:bf:1a:0c:22 | 198.51.100.60:123 time.example.org AS13335 | UDP | — | vlan 10 if 3→9 | 76 B | 1 |
| 14:21:58 | 203.0.113.77:44120 | 192.0.2.10:22 gateway.lan | TCP | S | vlan 1 if 9→2 | 60 B | 1 |
| 14:21:44 | 192.0.2.58:49339 camera-front.lan 74:ac:b9:5d:11:8e | 192.0.2.10:7442 nvr.lan | TCP | PA | vlan 20 if 4→4 | 1.2 MB | 904 |
Interfaces, MAC addresses, VLAN tags, DSCP markings and BGP AS numbers are decoded from the exporter — not just the 5-tuple. Public addresses are reverse-resolved.
Interface shown with representative data. Addresses are from reserved documentation ranges.
Your network is already talking
Start hearing what matters.
Connect your first UniFi site in minutes. Explore every Pro feature free for 14 days—no credit card required.