Open Source · Self-Hosted

Your UniFi firewall logs, finally useful

Capture every syslog event, enrich with GeoIP & threat scores, visualize traffic flows with Sankey graphs, and manage firewall syslog in bulk - from a single Docker container.

$
docker pull ghcr.io/jmasarweh/unifi-log-insight:latest

Deep visibility into every firewall event

Enriched logs, interactive Sankey graphs, a live threat map, and bulk syslog management - everything UniFi's built-in traffic view leaves out.

Features - click any card to explore
Browser Extension
ChromeFirefoxEdge

Threat intelligence inside your UniFi controller

The companion browser extension brings Insights Plus data directly into your UniFi Network Controller - no tab-switching required.

Threat Badges in Flow View

Every flow in your UniFi controller gets an inline threat score badge. See at a glance which connections involve known malicious IPs.

Side Panel Enrichment

Click any flow row and the detail panel shows AbuseIPDB threat score, rDNS hostname, ASN/ISP, abuse categories, and blacklist status.

Embedded Dashboard Tab

An "Insights Plus" tab appears in your UniFi controller's navigation, embedding your full dashboard without leaving the controller.

Dark/Light Mode

Automatically matches your UniFi controller's theme. All injected UI adapts seamlessly to both modes.

UniFi controller with Insights Plus tab injection and enriched flow records
Insights Plus browser extension popup showing traffic overview and connection status
Insights Plus threat map embedded inside UniFi controller showing global threat origins

Ready to see what your firewall is doing?

Get up and running in minutes. Single Docker container, no external dependencies, zero data collection.

$
docker pull ghcr.io/jmasarweh/unifi-log-insight:latest