⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | UniFi Site Manager (CCF) |
| Support Tier | Community |
| Support Link | https://github.com/Azure/Azure-Sentinel/issues |
| Categories | Networking,Security - Network |
| Version | 3.0.0 |
| Author | noodlemctwoodle - ccfconnectors.county118@passmail.com |
| First Published | 2026-05-11 |
| Last Updated | 2026-05-11 |
| Solution Folder | UniFi Site Manager (CCF) |
The UniFi Site Manager solution for Microsoft Sentinel provides cloud-side telemetry ingestion via the Site Manager API for sites, devices, hosts and ISP metrics. Ships analytics rules covering ISP downtime, WAN issues, IPS/IDS posture, firmware drift, device offline events, configuration changes and security signals, plus an operations workbook for at-a-glance estate health.
Data Connector: UniFi Site Manager (CCF) — single Connect deploys 4 polling rules with a single API key.
Underlying API tier: the Site Manager API is available on all UniFi cloud plans. The Audit log endpoint requires Pro+; this solution does not depend on it.
Pre-requisites: A UniFi Site Manager API key is required. Generate one at https://unifi.ui.com/api.
This solution provides 1 data connector(s):
This solution uses 4 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
Unifi_SiteManager_Devices_CL |
UniFi Site Manager (CCF) | Analytics, Hunting, Workbooks |
Unifi_SiteManager_Hosts_CL |
UniFi Site Manager (CCF) | Analytics, Hunting, Workbooks |
Unifi_SiteManager_ISPMetrics_CL |
UniFi Site Manager (CCF) | Analytics, Hunting, Workbooks |
Unifi_SiteManager_Sites_CL |
UniFi Site Manager (CCF) | Analytics, Hunting, Workbooks |
The following 1 table(s) are used internally by this solution's content items:
| Table | Used By Connectors | Used By Content |
|---|---|---|
SecurityIncident |
- | Workbooks |
This solution includes 31 content item(s):
| Content Type | Count |
|---|---|
| Analytic Rules | 22 |
| Hunting Queries | 8 |
| Workbooks | 1 |
| Name | Tables Used |
|---|---|
| UnifiSiteManager | Unifi_SiteManager_Devices_CLUnifi_SiteManager_Hosts_CLUnifi_SiteManager_ISPMetrics_CLUnifi_SiteManager_Sites_CLInternal use: SecurityIncident |
📄 Source: UniFi Site Manager (CCF)/README.md
The UniFi Site Manager solution for Microsoft Sentinel ingests cloud-side telemetry from the UniFi Site Manager API and ships analytics rules + a workbook for monitoring UniFi-managed networks.
Unifi_SiteManager_Sites_CL, Unifi_SiteManager_Devices_CL, Unifi_SiteManager_Hosts_CL, Unifi_SiteManager_ISPMetrics_CLSite Manager API endpoints used by this connector are available on all UniFi cloud plans. The connector does not depend on UniFi network flow logs or the audit log API, both of which require Pro+.
State-based rules (IPS/IDS disabled, WAN issues, critical notifications, system-log shipping disabled) fire only on state transitions — they detect the change from enabled → disabled, not the persistent state. This keeps incident volume proportional to actual events and avoids alert storms during sustained outages.
ISP performance rules (downtime, latency, packet loss, SLA) operate on rolling windows of the Unifi_SiteManager_ISPMetrics_CL table.
This is a community-supported solution maintained by Fetch Labs. File issues at https://github.com/noodlemctwoodle/Azure-Sentinel/issues.
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.0 | 22-05-2026 | Initial Solution Release - UniFi Site Manager (CCF) with single-card multi-poller (sites, hosts, devices, ISP metrics), 22 analytic rules, 8 hunting queries, operations workbook and Unifi_SiteManager_* custom tables |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊