↳ GitHub sourceConnector

Akamai Security Events (via Codeless Connector Framework)

Description

The [Akamai SIEM Connector](https://techdocs.akamai.com/siem-integration/docs) ingests web application firewall (WAF) security events from the [Akamai SIEM Integration API](https://techdocs.akamai.com/siem-integration/reference/get-config) into Microsoft Sentinel. The connector collects detailed security event data including attack information, geographic context, and HTTP request/response metadata. Authentication uses Akamai EdgeGrid - provide your three EdgeGrid credentials (client_token, access_token, client_secret) plus the API hostname from your .edgerc file. The platform runtime computes a fresh HMAC-SHA-256 signed Authorization header on every poll request per the EdgeGrid specification.
Declared status
1
Declared author / publisher
Akamai

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Akamai EdgeGrid API Credentials
**Client Token**, **Access Token**, and **Client Secret** are required for EdgeGrid HMAC-SHA-256 authentication. These credentials are generated from the [Akamai Control Center](https://control.akamai.com/) under **Identity & Access** > **API Clients**.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Step 1 - Enable Data Collection for SIEM in Akamai Security Center
Turn on SIEM integration in your Akamai security configuration and note the Web Security Configuration ID.
Step 2 - Provision EdgeGrid API credentials
Create an Akamai EdgeGrid API client with the Manage SIEM role and download the .edgerc credentials file.
Step 3 - Connect Akamai SIEM to Microsoft Sentinel
Add Connection
Configure Akamai SIEM API Connection
Akamai Hostname (from .edgerc "host" field)
SIEM Config ID(s)
Client Token (from .edgerc "client_token" field)
Access Token (from .edgerc "access_token" field)
Client Secret (from .edgerc "client_secret" field)

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
AkamaiSIEMConnector
Additional source files 2Solutions/Akamai DDOS Protection/Data Connectors/AkamaiDDOSProtection_CCF/AkamaiDDOSProtection_ConnectorDefinition.jsonsource ↗Solutions/Akamai DDOS Protection/Data/Solution_AkamaiDDOSProtection.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.