๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

UniFi Monitoring

Watch your clients' Ubiquiti UniFi networks for outdated firmware, risky settings and signs of compromise, all from one screen.

Where to find it
Network โ€บ Ubiquiti
Who can use it
Anyone who can see the page. Acknowledging alerts and triggering backups may be limited to administrators.
Plan
Ubiquiti / UniFi monitoring
For
Everyone

What the page is for

UniFi Monitoring shows what Lavawall collects from the UniFi controllers you connect on the Controllers page. For one company, it lists every UniFi device with its firmware, state, CPU, memory and patch status; the console and site users; security settings; configuration backups; and sites.

It also watches for indicators of compromise and reliability problems, such as a new administrator being added, an admin login from a new or unusual location, a known-bad admin account, remote access being turned on, firewall or port-forward changes, firmware downgrades, devices going offline, the internet uplink going down, and backups not running. Each one becomes an alert you can acknowledge.

Choose All companies in the company picker to see a combined overview across every company with UniFi.

What you see

The UniFi Monitoring page, with the summary cards, open alerts, controller status, devices & patch status, console & site users and recent indicators of compromise numbered 1 to 6.
The UniFi Monitoring page. Numbers match the list below.
  1. Summary cards: Controllers (reporting OK), Unreachable controllers, Devices needing updates, Open indicators of compromise (last 30 days) and Events (last 30 days).
  2. Open alerts: unacknowledged alerts with severity and an Acknowledge button.
  3. Controller status: each controller with its address and last poll time.
  4. Devices & patch status: Device, Model, Controller, Firmware, State, CPU, Mem and Patch status.
  5. Console & site users, Security posture, Configuration backups and Sites: who has access, key security settings, recent backups and the sites on each controller.
  6. Recent indicators of compromise: Severity, Type, Controller, Subject, Summary and Time, with Show acknowledged and Refresh; click a row for Indicator detail.

How to use UniFi Monitoring

How to set up monitoring

  1. Select the company.
  2. If you see "No UniFi controllers set up for this company", click Set up a controller, or click Controllers at the top.
  3. After you add a controller, this page refreshes automatically while it waits for the first poll.

How to deal with alerts

  1. Review Open alerts, starting with Critical and High.
  2. Investigate the change on the controller.
  3. Click Acknowledge once you have confirmed it was expected or fixed it.

How to find devices that need firmware updates

  1. Check the Devices needing updates card.
  2. In Devices & patch status, look for Update available in Patch status.
  3. Hover the firmware version to see where the reading came from.

How to review who has access

  1. Open Console & site users.
  2. Look for unexpected names, super-admin badges, default account names and unfamiliar Last login IP addresses.

How to take a configuration backup

  1. In Configuration backups, click Back up (controller name).
  2. This is only available for local (direct) connections; cloud connections are read-only.

How to review past indicators

  1. In Recent indicators of compromise, turn on Show acknowledged to include ones already handled.
  2. Click Refresh to reload, and click a row to see the Indicator detail.

Tips

  • Severity colours: red is Critical, amber is High, blue is Medium and grey is Low.
  • The page refreshes itself shortly after each controller's next scheduled poll.
  • Alerts also appear in Notifications, and can be emailed to subscribers from Notification Setup.
  • Admin, backup and login checks need a local or agent-relayed connection; a cloud-only connection covers device inventory and firmware.

Troubleshooting

  • "No UniFi controllers set up for this company". Add one with Set up a controller.
  • "No open alerts." Nothing needs attention right now.
  • Unreachable controllers is above zero. Open Controllers and check the status and error for that controller.
  • "Triggering a backup requires a local (direct) controller connection". The cloud connection cannot start backups. Add a local connection if you need this.
  • CPU and memory show a dash. With a cloud connection this needs an owner-generated API key and a console that supports the cloud connector. See UniFi Controllers.

Task guides that use this page

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.