Ubiquiti UniFi
You can integrate Ubiquiti UniFi with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Ubiquiti UniFi product overview
Ubiquiti UniFi Gateway is a network security appliance that manages and monitors network traffic and applies predefined security rules to protect the network, administered centrally through the UniFi Network platform. Supported gateway models include the USG, UXG, and UDM families.
What we ingest
Sophos XDR collects Ubiquiti UniFi Gateway data via syslog. The integration processes intrusion detection and prevention (IDS/IPS) security-detection messages generated by UniFi gateways, identified from valid Common Event Format (CEF) records. The following is collected:
- IDS/IPS security detections: Network intrusion detection and prevention alerts raised by the gateway's threat-detection engine, carrying the alert title and category, the matching signature name and identifier, severity, and the source and destination address, port, and protocol.
Event and data types
We ingest the following event and data types from Ubiquiti UniFi:
- Network intrusion detection and prevention: IDS/IPS alerts such as attempted privilege gain, misc attack, potentially bad traffic, port-scan detection, policy violations, and blocklist matches, each with its signature, severity, and connection details. Normalized to third-party security alert telemetry.
Data provided by this integration
Data provided by Ubiquiti UniFi gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
- UniFi System Logs & SIEM Integration
- UniFi Gateway - Intrusion Detection and Prevention (IDS/IPS)
- UDM SE - threat detection alerts