September 24, 2026
UniFi App for Splunk
Enriches UniFi device syslog MAC addresses with friendly names, IPs, and hardware vendors by correlating TA_unifi_ng telemetry with SC4S syslog, providing dashboards for topology, WiFi experience, and network operations.Built by Hans-Henning GehrtsSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
The UniFi App for Splunk correlates and enriches UniFi network device syslog data with telemetry and asset information collected by the TA_unifi_ng add-on. UniFi devices emit syslog messages containing only MAC addresses, making troubleshooting difficult. This app bridges the gap by performing search-time enrichment that translates device and client MAC addresses into friendly names, IP addresses, device models, and hardware vendor information. The app ingests syslog data via Splunk Connect for Syslog (SC4S) with sourcetypes ubnt, ubnt:wireless, and ubnt:dns, then cross-references this data against UniFi Integration API telemetry to build dynamic lookups. Seven dashboards provide topology visualization, network overview metrics, device and client drilldowns, WiFi experience analysis including roaming events, and auditing capabilities. Two scheduled saved searches rebuild device and client lookups every 15 minutes, ensuring enrichment data remains current as the network changes. The app is designed for network operations teams managing UniFi controllers and requires both API telemetry collection via TA_unifi_ng and syslog forwarding from UniFi devices to SC4S.
Log in to report this app listing.