September 22, 2026
UniFi Network Add-on for Splunk
Collects UniFi Network controller inventory, telemetry, and reference data via Integration API v1, mapping devices, clients, networks, and performance metrics to CIM for Enterprise Security and ITSI.Built by Hans-Henning GehrtsSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 8.x, 6.x, 5.x, 4.x
Log in to rate this app
The UniFi Network Add-on for Splunk polls UniFi Network controllers via the Integration API v1 to collect network infrastructure inventory, telemetry, and reference data. The add-on retrieves configuration details for sites, devices, clients, networks, firewall policies, WiFi broadcasts, VPN servers, DNS policies, and hotspot vouchers. It also collects per-device performance statistics and large reference datasets such as country codes and DPI application classifications. All data is indexed into Splunk with structured source types that correspond to specific UniFi configuration objects and metrics. The add-on maps UniFi events and inventory to the Common Information Model (CIM) domains for Inventory, Network Traffic, Network Sessions, and Performance, enabling integration with Splunk Enterprise Security and IT Service Intelligence (ITSI). Dashboards provide visibility into client activity, network health, and device performance. API credentials are stored encrypted, and the add-on operates in read-only mode.
Log in to report this app listing.