Description
The Akamai Guardicore connector uses the Codeless Connector Framework (CCF) to import Agents, Assets, Applications, and Policy Rules from a Guardicore Centra instance into Microsoft Sentinel via Data Collection Rule (DCR) ingestion. The connector polls every 10 minutes via Microsoft Sentinel's CCF runtime; no Azure Function App is deployed.
- Declared status
- 1
- Declared author / publisher
- Akamai
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and write permissions on the workspace are required.
Workspace
Workspace
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect Akamai Guardicore to Microsoft Sentinel
**Prerequisites**
1. You must have a reachable Akamai Guardicore Centra management instance with API access enabled.
2. Create (or obtain) an API user in Guardicore Centra with the **Read-only** role. This account must be authorized to call `/api/v3.0/authenticate`, `/api/v3.0/agents`, `/api/v3.0/assets`, `/api/v3.0/workflow/projects`, and `/api/v3.0/visibility/policy/rules`.
3. Have the Guardicore management URL (for example `https://<tenant>.cloud.guardicore.com`) and the service-account username and password ready.
4. The connector polls every 10 minutes via Microsoft Sentinel's CCF runtime. No Azure Function App is deployed.
Provide your Guardicore Centra service-account details and click **Connect** to start polling.
Guardicore Management URL
Guardicore Username
Guardicore Password
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
7ca9800↗- Source identifier
AkamaiGuardicore
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC