Description
The [UniFi Site Manager](https://unifi.ui.com/) solution for Microsoft Sentinel provides cloud-side telemetry ingestion via the [Site Manager API](https://developer.ui.com/site-manager-api/) for sites, devices, hosts and ISP metrics. Ships analytics rules covering ISP downtime, WAN issues, IPS/IDS posture, firmware drift, device offline events, configuration changes and security signals, plus an operations workbook for at-a-glance estate health.
**Data Connector:** UniFi Site Manager (CCF) — single Connect deploys 4 polling rules with a single API key.
**Underlying API tier:** the Site Manager API is available on all UniFi cloud plans. The Audit log endpoint requires Pro+; this solution does not depend on it.
**Pre-requisites:** A UniFi Site Manager API key is required. Generate one at https://unifi.ui.com/api.
- Version
- 3.0.0
- Declared author / publisher
- noodlemctwoodle - ccfconnectors.county118@passmail.com
- Support tier
- Community
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
azure-sentinel-solution-unifisitemanager
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC