Skip to main content

Akamai WAF connector FAQ

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Akamai WAF from the Previews page. See Manage Databricks previews.

Common questions about the managed Akamai WAF ingestion connector: required Akamai roles, supported tables, the 12-hour SIEM retention window, and EdgeGrid authentication. For FAQs that apply to all managed connectors, see Managed connector FAQs.

Which Akamai roles and API access does the connector require?​

Create an API client as a user with the Manage SIEM role, and grant that client READ-ONLY access to the SIEM API. Turn on SIEM Integration and data collection for each security configuration you ingest. See Configure authentication to Akamai.

Which tables does the connector support?​

The connector supports the akamai_waf_events table only. For the destination schema, see Destination table schemas.

How far back can the connector ingest data?​

Akamai retains SIEM events for 12 hours. The first sync starts from that 12-hour window, and each later sync continues from the last offset. The connector can't ingest events older than 12 hours. Schedule the pipeline to run at least every 12 hours. See Akamai WAF connector limitations.

Which authentication methods does the connector support?​

The connector supports Akamai EdgeGrid API client credentials only (host, client token, client secret, and access token). OAuth U2M, OAuth M2M, and basic authentication with a username and password aren't supported.

What are configuration IDs?​

Each Akamai security configuration has a Web Security Configuration ID. Pass one or more of these IDs in the config_ids pipeline option so the connector can fetch SIEM events for those configurations. You can specify 1 to 1,000 IDs. See Fetch Web Security Configuration IDs.