Overview
The Akamai integration uses the Akamai SIEM API (siem-api) to ingest events generated by:
- Kona Site Defender / App & API Protector (WAF rule hits, rate controls)
- Bot Manager (bot category, action, score)
- Client Reputation decisions
- Custom rules
Prerequisites
- An Akamai Control Center account with permission to create API clients.
- A configured Security Configuration with SIEM Integration enabled.
Step 1: Create an API client in Akamai Control Center
- Sign in to Akamai Control Center at https://control.akamai.com.
- Go to Identity & Access → API Clients → Create API Client.
- Choose Quick or Advanced and grant the following service:
- SIEM (
Read-Only)
- SIEM (
- Save the client. Akamai displays a credentials block containing:
client_tokenclient_secretaccess_tokenhost
Copy all four values.
Step 2: Enable SIEM on a Security Configuration
- Go to Security → Security Configurations.
- Open the configuration you want to ingest from and select the SIEM Integration tab.
- Enable SIEM for the relevant security policies and click Save.
Step 3: Connect Akamai in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the Akamai card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Host | Akamai API host. | akab-xxxx.luna.akamaiapis.net |
| Client Token | client_token from Step 1. |
akab-xxxx |
| Client Secret | client_secret from Step 1. |
•••••••• |
| Access Token | access_token from Step 1. |
akab-xxxx |
| Config IDs | Comma-separated security configuration IDs. | 12345,67890 |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The Akamai card shows Configured.
- WAF and bot events appear in Security → Cloud SIEM → Audit Logs → Events with source
akamai.
+1-415-800-4104