⚠️ UniFi Site Manager (CCF)

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

UniFi Site Manager (CCF) Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index


Attribute Value
Publisher UniFi Site Manager (CCF)
Support Tier Community
Support Link https://github.com/Azure/Azure-Sentinel/issues
Categories Networking,Security - Network
Version 3.0.0
Author noodlemctwoodle - ccfconnectors.county118@passmail.com
First Published 2026-05-11
Last Updated 2026-05-11
Solution Folder UniFi Site Manager (CCF)

The UniFi Site Manager solution for Microsoft Sentinel provides cloud-side telemetry ingestion via the Site Manager API for sites, devices, hosts and ISP metrics. Ships analytics rules covering ISP downtime, WAN issues, IPS/IDS posture, firmware drift, device offline events, configuration changes and security signals, plus an operations workbook for at-a-glance estate health.

Data Connector: UniFi Site Manager (CCF) — single Connect deploys 4 polling rules with a single API key.

Underlying API tier: the Site Manager API is available on all UniFi cloud plans. The Audit log endpoint requires Pro+; this solution does not depend on it.

Pre-requisites: A UniFi Site Manager API key is required. Generate one at https://unifi.ui.com/api.

Contents

Data Connectors

This solution provides 1 data connector(s):

Tables Used

This solution uses 4 table(s):

Table Used By Connectors Used By Content
Unifi_SiteManager_Devices_CL UniFi Site Manager (CCF) Analytics, Hunting, Workbooks
Unifi_SiteManager_Hosts_CL UniFi Site Manager (CCF) Analytics, Hunting, Workbooks
Unifi_SiteManager_ISPMetrics_CL UniFi Site Manager (CCF) Analytics, Hunting, Workbooks
Unifi_SiteManager_Sites_CL UniFi Site Manager (CCF) Analytics, Hunting, Workbooks

Internal Tables

The following 1 table(s) are used internally by this solution's content items:

Table Used By Connectors Used By Content
SecurityIncident - Workbooks

Content Items

This solution includes 31 content item(s):

Content Type Count
Analytic Rules 22
Hunting Queries 8
Workbooks 1

Analytic Rules

Name Severity Tactics Tables Used
UniFi Site Manager: Console firmware likely security-relevant High InitialAccess Unifi_SiteManager_Devices_CL
UniFi Site Manager: Controller Connection State Change Medium Impact, CommandAndControl Unifi_SiteManager_Hosts_CL
UniFi Site Manager: Data Connector Health Medium DefenseEvasion Unifi_SiteManager_Devices_CL
Unifi_SiteManager_Hosts_CL
Unifi_SiteManager_ISPMetrics_CL
Unifi_SiteManager_Sites_CL
UniFi Site Manager: Device Offline Medium Impact Unifi_SiteManager_Devices_CL
UniFi Site Manager: External WAN IP changed High Reconnaissance Unifi_SiteManager_Sites_CL
UniFi Site Manager: Firmware Update Available Low InitialAccess Unifi_SiteManager_Devices_CL
UniFi Site Manager: IPS signature count dropped >50% Medium DefenseEvasion Unifi_SiteManager_Sites_CL
UniFi Site Manager: IPS/IDS disabled or misconfigured High DefenseEvasion Unifi_SiteManager_Sites_CL
UniFi Site Manager: ISP Downtime High Impact Unifi_SiteManager_ISPMetrics_CL
UniFi Site Manager: ISP High Latency Medium Impact Unifi_SiteManager_ISPMetrics_CL
UniFi Site Manager: ISP Packet Loss Medium Impact Unifi_SiteManager_ISPMetrics_CL
UniFi Site Manager: ISP SLA Breach Medium Impact Unifi_SiteManager_ISPMetrics_CL
UniFi Site Manager: Multiple Devices Offline High Impact Unifi_SiteManager_Devices_CL
UniFi Site Manager: New Device Adopted Informational InitialAccess, Persistence Unifi_SiteManager_Devices_CL
UniFi Site Manager: New WAN issue index recorded Medium Impact Unifi_SiteManager_Sites_CL
UniFi Site Manager: New WAN2 (secondary) issue recorded Medium Impact Unifi_SiteManager_Sites_CL
UniFi Site Manager: New critical notifications appeared Medium Impact Unifi_SiteManager_Sites_CL
UniFi Site Manager: Pending firmware updates outstanding for 7d+ Low Reconnaissance Unifi_SiteManager_Sites_CL
UniFi Site Manager: Site Health Critical High Impact Unifi_SiteManager_Sites_CL
UniFi Site Manager: System log shipping disabled High DefenseEvasion Unifi_SiteManager_Hosts_CL
UniFi Site Manager: WAN uptime below 99% Medium Impact Unifi_SiteManager_Sites_CL
UniFi Site Manager: WiFi quality degraded (high TX retry) Low Impact Unifi_SiteManager_Sites_CL

Hunting Queries

Name Tactics Tables Used
UniFi Site Manager: Console group membership churn Persistence Unifi_SiteManager_Hosts_CL
UniFi Site Manager: Devices adopted outside business hours Persistence Unifi_SiteManager_Devices_CL
UniFi Site Manager: Devices flapping online/offline Impact Unifi_SiteManager_Devices_CL
UniFi Site Manager: Firmware drift hotspots Reconnaissance Unifi_SiteManager_Devices_CL
UniFi Site Manager: Firmware version diversity within a model Reconnaissance Unifi_SiteManager_Devices_CL
UniFi Site Manager: Long-tail ISP latency hotspots (P95) Impact Unifi_SiteManager_ISPMetrics_CL
UniFi Site Manager: Sites with persistent WAN issues Impact Unifi_SiteManager_Sites_CL
UniFi Site Manager: WAN external IP geographic deviation Reconnaissance Unifi_SiteManager_Sites_CL

Workbooks

Name Tables Used
UnifiSiteManager Unifi_SiteManager_Devices_CL
Unifi_SiteManager_Hosts_CL
Unifi_SiteManager_ISPMetrics_CL
Unifi_SiteManager_Sites_CL
Internal use:
SecurityIncident

Additional Documentation

📄 Source: UniFi Site Manager (CCF)/README.md

UniFi Site Manager

The UniFi Site Manager solution for Microsoft Sentinel ingests cloud-side telemetry from the UniFi Site Manager API and ships analytics rules + a workbook for monitoring UniFi-managed networks.

Contents

Pre-requisites

  1. A Microsoft Sentinel-enabled Log Analytics workspace.
  2. A Data Collection Endpoint (DCE) in the same region.
  3. A UniFi Site Manager API key. Generate one at https://unifi.ui.com/api (Site Manager → Account → API → Create API Key). Required scope: Audit Logs - Read is optional; the four ingestion endpoints used here do not require it.

Connect

  1. Microsoft Sentinel → Content hub → install the UniFi Site Manager solution.
  2. Sentinel → Data connectors → search "UniFi Site Manager (CCF)"Open connector page.
  3. Paste your API key → Connect. All four poll rules instantiate from a single click.

Tier requirements

Site Manager API endpoints used by this connector are available on all UniFi cloud plans. The connector does not depend on UniFi network flow logs or the audit log API, both of which require Pro+.

Analytics rule strategy

State-based rules (IPS/IDS disabled, WAN issues, critical notifications, system-log shipping disabled) fire only on state transitions — they detect the change from enabled → disabled, not the persistent state. This keeps incident volume proportional to actual events and avoids alert storms during sustained outages.

ISP performance rules (downtime, latency, packet loss, SLA) operate on rolling windows of the Unifi_SiteManager_ISPMetrics_CL table.

Support

This is a community-supported solution maintained by Fetch Labs. File issues at https://github.com/noodlemctwoodle/Azure-Sentinel/issues.

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 22-05-2026 Initial Solution Release - UniFi Site Manager (CCF) with single-card multi-poller (sites, hosts, devices, ISP metrics), 22 analytic rules, 8 hunting queries, operations workbook and Unifi_SiteManager_* custom tables

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Solutions Index