Overview

The Akamai integration uses the Akamai SIEM API (siem-api) to ingest events generated by:

  • Kona Site Defender / App & API Protector (WAF rule hits, rate controls)
  • Bot Manager (bot category, action, score)
  • Client Reputation decisions
  • Custom rules

Prerequisites

  • An Akamai Control Center account with permission to create API clients.
  • A configured Security Configuration with SIEM Integration enabled.

Step 1: Create an API client in Akamai Control Center

  1. Sign in to Akamai Control Center at https://control.akamai.com.
  2. Go to Identity & Access → API Clients → Create API Client.
  3. Choose Quick or Advanced and grant the following service:
    • SIEM (Read-Only)
  4. Save the client. Akamai displays a credentials block containing:
    • client_token
    • client_secret
    • access_token
    • host

Copy all four values.


Step 2: Enable SIEM on a Security Configuration

  1. Go to Security → Security Configurations.
  2. Open the configuration you want to ingest from and select the SIEM Integration tab.
  3. Enable SIEM for the relevant security policies and click Save.

Step 3: Connect Akamai in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the Akamai card and click Connect.
  3. Fill in the form:
Field Description Example
Host Akamai API host. akab-xxxx.luna.akamaiapis.net
Client Token client_token from Step 1. akab-xxxx
Client Secret client_secret from Step 1. ••••••••
Access Token access_token from Step 1. akab-xxxx
Config IDs Comma-separated security configuration IDs. 12345,67890
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The Akamai card shows Configured.
  • WAF and bot events appear in Security → Cloud SIEM → Audit Logs → Events with source akamai.