Skip to main content

Set up

  1. Follow the shared Log Forwarders guide to add Ubiquiti UniFi Network and open Forwarder Details (or ask Chat for the listener ip:port)
  2. Point UniFi logging at the Wirespeed IP and port from Forwarder Details using the options below
  3. Events should begin appearing shortly under Events
Navigation and field labels below match UniFi OS 5.1.x and Network 10.6.x. UniFi exposes two syslog pages that send different event classes.
Sending the same log categories through both pages to the same Wirespeed listener produces duplicate events (especially Updates). You can use both pages when you need UniFi OS events and gateway/security logs — leave overlapping categories enabled on only one page. If duplicates appear, disable the extra syslog destination.

Option A — Integrations: System Logging / SIEM (CEF)

Use this path for UniFi OS system events in CEF format. It does not include firewall or security detections — those are on Option B.
  1. In UniFi Network, open IntegrationsSystem Logging / SIEM
  2. Select SIEM Server
  3. Choose log categories — at minimum System (under UniFi OS; also available: Updates, Admins, Backups, Users)
  4. Enter the Wirespeed listener IP Address from Forwarder Details
  5. Enter the Wirespeed listener Port
  6. Click Save

Option B — CyberSecure: Traffic Logging (classic gateway syslog)

Use this path for gateway firewall, DHCP, and Security Detections. This is the path that covers firewall policy and security logs.
  1. In UniFi Network, open CyberSecureTraffic Logging
  2. Under Activity Logging (Syslog), select SIEM Server
  3. Choose Contents categories — for example Gateway, Security Detections, Firewall Default Policy, Updates, and Critical
  4. Leave Debug Logs unchecked unless you are troubleshooting
  5. Enter the Wirespeed listener Server Address from Forwarder Details
  6. Enter the Wirespeed listener Port
  7. Save the configuration
Wirespeed auto-detects format per event: CEF when the line contains CEF:0|…, otherwise classic UniFi syslog.
UniFi Access and UniFi Protect are not covered by this integration.