Akamai Web Security Integration
Overview
Akamai provides web application firewall, DDoS protection, and bot management through its cloud security platform. KYRA MDR collects Akamai security events via the SIEM Integration API for web threat detection.
Prerequisites
- A KYRA MDR Collector installed and running
- Akamai account with Security Configuration
- SIEM Integration API access credentials
- Akamai {OPEN} API client with SIEM access
Configuration
Configure Akamai SIEM API integration:
- Create an API client in the Akamai Control Center:
- Navigate to Identity & Access > API Users
- Create a client with SIEM access
- Note the credentials (client_secret, host, access_token, client_token)
- Configure the KYRA MDR collector:
sources: - type: akamai host: <api-host>.luna.akamaiapis.net client_secret: <client-secret> client_token: <client-token> access_token: <access-token> config_ids: ["12345"] poll_interval: 30s- Restart the collector service
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| WAF Events | Web application firewall alerts | Web attack detection |
| DDoS Events | Distributed denial of service events | Volumetric attack mitigation |
| Bot Events | Bot detection and classification | Automated threat management |
| API Security | API abuse and anomaly events | API protection |
| Client Reputation | IP reputation scoring | Threat intelligence |
| Rate Control | Rate limiting events | Abuse prevention |
Troubleshooting
No SIEM data: Verify the API client has SIEM read access and the configuration ID is correct.
Data delay: Akamai SIEM API has a delay of 2-3 minutes for event availability.
Rate limiting: Set the poll interval to at least 30 seconds and handle HTTP 429 responses.
Contact kyra@seekerslab.com for support.