Back
Idac1efe0f-654e-264e-07be-c1b60e698343
RulenameUniFi Site Manager: Controller Connection State Change
DescriptionIdentifies when a UniFi controller (Cloud Key, Dream Machine, etc.) experiences a connection state change, which may indicate a network outage, power loss, or device failure.
SeverityMedium
TacticsImpact
CommandAndControl
TechniquesT1489
T1071
Required data connectorsUniFiSiteManagerConnectorDefinition
KindScheduled
Query frequency15m
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudControllerConnectionStateChange.yaml
Version1.0.1
Arm templateac1efe0f-654e-264e-07be-c1b60e698343.json
Deploy To Azure
// UniFi Controller Connection State Change Detection
// Only fire when LastConnectionStateChange has changed since the prior 15-min cycle
// to avoid 4-5 alerts per actual state change (rule runs every 15m, change visible for 1h).
let prev = Unifi_SiteManager_Hosts_CL
    | where TimeGenerated between (ago(30m) .. ago(15m))
    | summarize arg_max(TimeGenerated, *) by Id
    | project id_s = Id, prevChange = todatetime(LastConnectionStateChange);
Unifi_SiteManager_Hosts_CL
| where TimeGenerated > ago(15m)
| where isnotempty(LastConnectionStateChange)
| summarize arg_max(TimeGenerated, *) by Id
| extend
    ConnectionChange = todatetime(LastConnectionStateChange),
    id_s = Id
| join kind=leftouter prev on id_s
| where ConnectionChange != prevChange or isnull(prevChange)
| where ConnectionChange > ago(30m)
| extend
    HostTypeDisplay = case(
        HostType == "ucore", "UniFi OS Console",
        HostType == "uck", "Cloud Key",
        HostType == "uckp", "Cloud Key+",
        HostType == "udm", "Dream Machine",
        HostType == "udmpro", "Dream Machine Pro",
        HostType == "udmse", "Dream Machine SE",
        HostType == "self-hosted", "Self-Hosted",
        HostType
    )
| project
    TimeGenerated,
    ConnectionChangeTime = ConnectionChange,
    PreviousChangeTime = prevChange,
    HostId = Id,
    HostType = HostType,
    HostTypeDisplay,
    IPAddress = IpAddress,
    IsBlocked = IsBlocked,
    IsOwner = Owner
subTechniques:
- T1071.001
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT4H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: true
  createIncident: true
name: 'UniFi Site Manager: Controller Connection State Change'
triggerOperator: gt
query: |
  // UniFi Controller Connection State Change Detection
  // Only fire when LastConnectionStateChange has changed since the prior 15-min cycle
  // to avoid 4-5 alerts per actual state change (rule runs every 15m, change visible for 1h).
  let prev = Unifi_SiteManager_Hosts_CL
      | where TimeGenerated between (ago(30m) .. ago(15m))
      | summarize arg_max(TimeGenerated, *) by Id
      | project id_s = Id, prevChange = todatetime(LastConnectionStateChange);
  Unifi_SiteManager_Hosts_CL
  | where TimeGenerated > ago(15m)
  | where isnotempty(LastConnectionStateChange)
  | summarize arg_max(TimeGenerated, *) by Id
  | extend
      ConnectionChange = todatetime(LastConnectionStateChange),
      id_s = Id
  | join kind=leftouter prev on id_s
  | where ConnectionChange != prevChange or isnull(prevChange)
  | where ConnectionChange > ago(30m)
  | extend
      HostTypeDisplay = case(
          HostType == "ucore", "UniFi OS Console",
          HostType == "uck", "Cloud Key",
          HostType == "uckp", "Cloud Key+",
          HostType == "udm", "Dream Machine",
          HostType == "udmpro", "Dream Machine Pro",
          HostType == "udmse", "Dream Machine SE",
          HostType == "self-hosted", "Self-Hosted",
          HostType
      )
  | project
      TimeGenerated,
      ConnectionChangeTime = ConnectionChange,
      PreviousChangeTime = prevChange,
      HostId = Id,
      HostType = HostType,
      HostTypeDisplay,
      IPAddress = IpAddress,
      IsBlocked = IsBlocked,
      IsOwner = Owner
queryFrequency: 15m
description: |
  Identifies when a UniFi controller (Cloud Key, Dream Machine, etc.) experiences a connection state change, which may indicate a network outage, power loss, or device failure.
id: ac1efe0f-654e-264e-07be-c1b60e698343
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.1
kind: Scheduled
status: Available
severity: Medium
requiredDataConnectors:
- connectorId: UniFiSiteManagerConnectorDefinition
  dataTypes:
  - Unifi_SiteManager_Hosts_CL
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudControllerConnectionStateChange.yaml
relevantTechniques:
- T1489
- T1071
tactics:
- Impact
- CommandAndControl
entityMappings:
- fieldMappings:
  - identifier: Address
    columnName: IPAddress
  entityType: IP
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/ac1efe0f-654e-264e-07be-c1b60e698343')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/ac1efe0f-654e-264e-07be-c1b60e698343')]",
      "properties": {
        "alertRuleTemplateName": "ac1efe0f-654e-264e-07be-c1b60e698343",
        "customDetails": null,
        "description": "Identifies when a UniFi controller (Cloud Key, Dream Machine, etc.) experiences a connection state change, which may indicate a network outage, power loss, or device failure.\n",
        "displayName": "UniFi Site Manager: Controller Connection State Change",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "IP",
            "fieldMappings": [
              {
                "columnName": "IPAddress",
                "identifier": "Address"
              }
            ]
          }
        ],
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": true,
            "lookbackDuration": "PT4H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/UniFi%20Site%20Manager%20%28CCF%29/Analytic%20Rules/UniFiCloudControllerConnectionStateChange.yaml",
        "query": "// UniFi Controller Connection State Change Detection\n// Only fire when LastConnectionStateChange has changed since the prior 15-min cycle\n// to avoid 4-5 alerts per actual state change (rule runs every 15m, change visible for 1h).\nlet prev = Unifi_SiteManager_Hosts_CL\n    | where TimeGenerated between (ago(30m) .. ago(15m))\n    | summarize arg_max(TimeGenerated, *) by Id\n    | project id_s = Id, prevChange = todatetime(LastConnectionStateChange);\nUnifi_SiteManager_Hosts_CL\n| where TimeGenerated > ago(15m)\n| where isnotempty(LastConnectionStateChange)\n| summarize arg_max(TimeGenerated, *) by Id\n| extend\n    ConnectionChange = todatetime(LastConnectionStateChange),\n    id_s = Id\n| join kind=leftouter prev on id_s\n| where ConnectionChange != prevChange or isnull(prevChange)\n| where ConnectionChange > ago(30m)\n| extend\n    HostTypeDisplay = case(\n        HostType == \"ucore\", \"UniFi OS Console\",\n        HostType == \"uck\", \"Cloud Key\",\n        HostType == \"uckp\", \"Cloud Key+\",\n        HostType == \"udm\", \"Dream Machine\",\n        HostType == \"udmpro\", \"Dream Machine Pro\",\n        HostType == \"udmse\", \"Dream Machine SE\",\n        HostType == \"self-hosted\", \"Self-Hosted\",\n        HostType\n    )\n| project\n    TimeGenerated,\n    ConnectionChangeTime = ConnectionChange,\n    PreviousChangeTime = prevChange,\n    HostId = Id,\n    HostType = HostType,\n    HostTypeDisplay,\n    IPAddress = IpAddress,\n    IsBlocked = IsBlocked,\n    IsOwner = Owner\n",
        "queryFrequency": "PT15M",
        "queryPeriod": "PT1H",
        "severity": "Medium",
        "status": "Available",
        "subTechniques": [],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "CommandAndControl",
          "Impact"
        ],
        "techniques": [
          "T1071",
          "T1489"
        ],
        "templateVersion": "1.0.1",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}