Enterprise Security forUniFi Networks

Purpose-built SIEM that integrates natively with every UniFi product. Monitor, detect, and respond to threats across your entire ecosystem.

Native UniFi Integration

Deep integration with every UniFi product for comprehensive visibility.

UniFi Network

Real-time monitoring of network events: IDS/IPS alerts, firewall drops, DHCP and wireless activity, WAN failover and controller changes — each handled by a dedicated parser.

  • Syslog & CEF ingestion
  • Severity taken from the syslog priority
  • Structured 5-tuple from firewall and IDS logs
  • Per-device inventory, auto-discovered

UniFi Protect

Smart-detection pipeline activity arrives over syslog. Full detection events come from the Protect Integration API or a signed webhook, once your console permits inbound access.

  • Protect Integration API polling
  • HMAC-signed webhook receiver
  • Detections correlated by event ID
  • Reachability preflight with a clear verdict

UniFi Access

Physical access control monitoring for doors, credentials and entry attempts, configured per tenant with its own API key.

  • Door and credential events
  • Tamper and forced entry raised as security
  • Per-tenant API key, encrypted at rest
  • Handles every Access response envelope

UniFi Talk

Roadmap

On the roadmap. Talk events are not yet parsed — we would rather tell you that than list a feature you cannot use today.

  • Planned: call detail records
  • Planned: SIP event logging

Powerful Capabilities

Everything you need to detect, investigate, and respond to security threats.

Detection Engine

Powerful YAML-based rule engine with support for complex conditions, aggregation, and correlation across multiple event sources.

  • YAML rule definitions
  • Regex pattern matching
  • Field aggregation (count events over time)
  • Multi-condition logic
  • Severity classification
  • Automatic alert generation

Multi-Channel Alerting

Get notified instantly through your preferred channels when security events occur.

  • Email notifications
  • Slack integration
  • Discord webhooks
  • PagerDuty escalation
  • Custom webhook delivery
  • Alert deduplication

AI-Powered Analysis

Ask Claude or GPT-5 to explain any event in plain English — what happened, why it matters, and what to do about it. Choose the provider and model per instance and bring your own key.

  • Natural language explanations
  • Threat context analysis
  • Remediation suggestions
  • Pattern recognition
  • Cached insights for speed
  • Configurable prompts

Threat Intelligence

Enrich events with external threat data to identify known malicious actors.

  • GeoIP location lookup
  • AbuseIPDB reputation
  • VirusTotal integration
  • ASN information
  • Malicious IP blocking
  • Intelligent caching

Active Response

Automatically respond to threats by taking action directly on your UniFi infrastructure.

  • Client blocking/quarantine
  • VLAN reassignment
  • Access credential disable
  • Rate limiting
  • Auto-revert with timers
  • Approval workflows

Elasticsearch Storage

Scalable, searchable storage for all your security events with powerful querying capabilities.

  • Full-text search
  • Complex aggregations
  • Time-based retention
  • Index lifecycle management
  • High availability support
  • Custom dashboards

Traffic Analytics (NetFlow / IPFIX)

See exactly what your network is doing. Ingests NetFlow v5, v9 and IPFIX and keeps the detail most collectors discard — switch port, MAC, VLAN, DSCP and BGP AS alongside the 5-tuple.

  • NetFlow v5, v9, and IPFIX (v10)
  • 60s tumbling-window aggregation
  • Top talkers by source, destination, or pair
  • Protocol breakdown (TCP/UDP/ICMP/etc.)
  • Sortable flow table: bytes, packets, time
  • Per-device drill-down and filtering

Network Event Viewer

Separate operational events from security events. Troubleshoot flapping ports, AP radar hits, WAN failovers, and controller provisioning without wading through IDS alerts.

  • Link up / down, port flaps, PoE state
  • AP radio: DFS radar, channel switch, CAC
  • WAN / VPN tunnel state (pppd, IPSec, OpenVPN)
  • Controller lifecycle: adopt, provision, upgrade
  • Dedicated Network Events page
  • Per-device event stream

SNMP Trap Receiver

Listen for v1 and v2c SNMP traps from UniFi switches and gateways. Well-known OIDs are mapped to human-readable names and severity levels.

  • SNMPv1 and SNMPv2c / INFORM
  • Well-known trap OID mapping (linkUp, authFailure, etc.)
  • Optional community-string filtering
  • Enterprise-specific OID pass-through
  • Full varbind capture in raw event
  • Mirrors into the Network Event feed

Structured UniFi Syslog Parsing

Instead of generic keyword matching, dedicated parsers extract the structured fields you need for hunting, correlation, and reporting.

  • iptables firewall: 5-tuple, rule name, action
  • Suricata IDS: signature ID, classification, priority
  • hostapd wireless: STA MAC, association state
  • dnsmasq DHCP: IP, MAC, hostname
  • Linux auth: SSH, PAM, login success/failure
  • Controller: device adoption, provision, upgrade

Multi-Tenant Admin Center

Run Sentinel for multiple clients from a single host. Every client gets their own isolated instance — data, rules, users, and alerts — with automated provisioning end-to-end.

  • One-click client instance provisioning
  • Automatic subdomain + DNS A record (GoDaddy API)
  • Wildcard SSL covering every instance
  • Super-admin SSO across all instances
  • Per-client resource limits and port allocation
  • Centralized rolling upgrades

Per-Tenant Ingest Isolation

Each client gets their own ports for syslog, NetFlow and SNMP, restricted at the firewall to the source addresses you nominate. The destination port alone decides which instance receives a packet.

  • Dedicated port per protocol, per tenant
  • Source-IP allow-listing enforced in iptables
  • No shared collector, no cross-tenant mixing
  • Ports listed in the Admin Center — no guessing
  • Set at creation, changeable later without data loss
  • Unrecognised senders dropped before ingestion

Credential Delivery

Every instance is provisioned with its own admin account. The password is encrypted at rest and can be emailed to the client with all of their ingest endpoints in one message.

  • Unique 20-character password per instance
  • AES-256-GCM encrypted at rest
  • Welcome email lists every allocated port
  • Reveal and send both write an audit entry
  • Resend to any address without retyping it
  • Machine secrets deliberately kept out of email

Backups & Retention

Your event history is the product, so it is snapshotted nightly and aged out on a schedule rather than growing until the disk fills.

  • Nightly Elasticsearch snapshots
  • Index lifecycle policy applied to every tenant
  • Warm tier at 7 days, deletion at 90
  • Inherited automatically by new instances
  • Tenant indices removed cleanly on deletion
  • Retention window configurable per plan

Noise Suppression

A flapping port or a chatty daemon can emit the same line thousands of times an hour. Repeats are collapsed into a single event with a count, so real signal stays visible.

  • Identical events collapsed with a repeat count
  • Numeric noise normalised before comparison
  • Original message always preserved
  • Alert rules see the aggregate, not the flood
  • Storage and query cost cut substantially
  • No configuration required

Device Inventory

Auto-discovered list of every device sending events. Click a device for its full event stream, or filter by device in the Network Events view.

  • Derived from event ingestion — no config
  • Last-seen and event-count per device
  • Device name, MAC, type, site
  • Per-device event drill-down endpoint
  • 30-day default look-back (configurable)
  • Surface-area for operational troubleshooting

Product, not promises

See exactly what your network is telling you.

Three of the views you'll live in: full-fidelity traffic analytics, operational events separated from security noise, and the multi-tenant Admin Center.

acme.sentinelnerd.com/flows

Flows

NetFlow v5 / v9 / IPFIX · aggregated by 5-tuple over a 60s window

Receiving
Flows (1h)
18,402
Traffic
4.8 GB
Top talker
camera-front
External peers
312
TimeSourceDestinationProtoFlagsVLAN / IfBytesPkts
14:22:07
192.0.2.41:51344
workstation-04.lan
8c:30:66:62:67:54
198.51.100.9:443
edge.cdn.example.net
AS15169
TCPPADSCP46
vlan 30
if 7→9
3.3 KB12
14:22:05
192.0.2.118:61708
ap-lobby.lan
f4:92:bf:1a:0c:22
198.51.100.60:123
time.example.org
AS13335
UDP
vlan 10
if 3→9
76 B1
14:21:58
203.0.113.77:44120
192.0.2.10:22
gateway.lan
TCPS
vlan 1
if 9→2
60 B1
14:21:44
192.0.2.58:49339
camera-front.lan
74:ac:b9:5d:11:8e
192.0.2.10:7442
nvr.lan
TCPPA
vlan 20
if 4→4
1.2 MB904

Interfaces, MAC addresses, VLAN tags, DSCP markings and BGP AS numbers are decoded from the exporter — not just the 5-tuple. Public addresses are reverse-resolved.

Interface shown with representative data. Addresses are from reserved documentation ranges.

Your network is already talking

Start hearing what matters.

Connect your first UniFi site in minutes. Explore every Pro feature free for 14 days—no credit card required.