Set up
- Follow the shared Log Forwarders guide to add Ubiquiti UniFi Network and open Forwarder Details (or ask Chat for the listener
ip:port) - Point UniFi logging at the Wirespeed IP and port from Forwarder Details using the options below
- Events should begin appearing shortly under Events
Navigation and field labels below match UniFi OS 5.1.x and Network 10.6.x. UniFi exposes two syslog pages that send different event classes.
Option A — Integrations: System Logging / SIEM (CEF)
Use this path for UniFi OS system events in CEF format. It does not include firewall or security detections — those are on Option B.- In UniFi Network, open Integrations → System Logging / SIEM
- Select SIEM Server
- Choose log categories — at minimum System (under UniFi OS; also available: Updates, Admins, Backups, Users)
- Enter the Wirespeed listener IP Address from Forwarder Details
- Enter the Wirespeed listener Port
- Click Save
Option B — CyberSecure: Traffic Logging (classic gateway syslog)
Use this path for gateway firewall, DHCP, and Security Detections. This is the path that covers firewall policy and security logs.- In UniFi Network, open CyberSecure → Traffic Logging
- Under Activity Logging (Syslog), select SIEM Server
- Choose Contents categories — for example Gateway, Security Detections, Firewall Default Policy, Updates, and Critical
- Leave Debug Logs unchecked unless you are troubleshooting
- Enter the Wirespeed listener Server Address from Forwarder Details
- Enter the Wirespeed listener Port
- Save the configuration
CEF:0|…, otherwise classic UniFi syslog.
UniFi Access and UniFi Protect are not covered by this integration.

