Prerequisites
To forward syslogs from Ubiquiti UniFi to LogCentral and benefit from our cloud based log storage, you'll need:
An active LogCentral location which will provide you with the IP & port to which you need to forward your syslogs. Don't forget to configure your own IP address(es) in your location.
Access to the settings of your UniFi network
Connect your UniFi admin console, for example through UniFi's cloud portal at https://unifi.ui.com/
Click on the picture to see it in a bigger size
Select your network and go to the settings of your network :
Click the Gears icon on the bottom left (number 1 in our screenshot above)
then on System (2 in our screenshot)
then on Integrations (3 in the screenshot)
finally on SIEM Server (number 4 in our screenshot).
Select the type of logs (5 in our screenshot) you want to forward to LogCentral. You can select all event types if needed.
In the server address, fill in the IP address available in your previously created LogCentral location for example in this screenshot, 49.12.218.35 is the server address and 15866 is the port you need to enter in UniFi's admin dashboard.
Here is how this information is presented in LogCentral:
Once finished, click "Apply changes" in UniFi's dashboard. (number 8 on our screenshot).
If everything is well in a few seconds or minutes you should see logs appearing in LogCentral.
Congrats!