본문으로 건너뛰기

Akamai Web Security Integration

Overview

Akamai provides web application firewall, DDoS protection, and bot management through its cloud security platform. KYRA MDR collects Akamai security events via the SIEM Integration API for web threat detection.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Akamai account with Security Configuration
  • SIEM Integration API access credentials
  • Akamai {OPEN} API client with SIEM access

Configuration

Configure Akamai SIEM API integration:

  1. Create an API client in the Akamai Control Center:
    • Navigate to Identity & Access > API Users
    • Create a client with SIEM access
  2. Note the credentials (client_secret, host, access_token, client_token)
  3. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: akamai
host: <api-host>.luna.akamaiapis.net
client_secret: <client-secret>
client_token: <client-token>
access_token: <access-token>
config_ids: ["12345"]
poll_interval: 30s
  1. Restart the collector service

Collected Log Types

Log TypeDescriptionSecurity Use
WAF EventsWeb application firewall alertsWeb attack detection
DDoS EventsDistributed denial of service eventsVolumetric attack mitigation
Bot EventsBot detection and classificationAutomated threat management
API SecurityAPI abuse and anomaly eventsAPI protection
Client ReputationIP reputation scoringThreat intelligence
Rate ControlRate limiting eventsAbuse prevention

Troubleshooting

No SIEM data: Verify the API client has SIEM read access and the configuration ID is correct.

Data delay: Akamai SIEM API has a delay of 2-3 minutes for event availability.

Rate limiting: Set the poll interval to at least 30 seconds and handle HTTP 429 responses.

Contact kyra@seekerslab.com for support.