Skip to main content

Ingest data from Akamai

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Akamai WAF from the Previews page. See Manage Databricks previews.

Create a managed Akamai WAF ingestion pipeline in Lakeflow Connect to ingest WAF security events into Databricks.

Requirements​

  • To create an ingestion pipeline, first meet the following requirements:

    • Your workspace must be enabled for Unity Catalog.

    • Serverless compute must be enabled for your workspace. See Serverless compute requirements.

    • To create a new connection, you must have CREATE CONNECTION privileges on the metastore. See Manage privileges in Unity Catalog.

      If the connector supports UI-based pipeline authoring, an admin can create the connection and the pipeline at the same time by completing the steps on this page. However, if the users who create pipelines use API-based pipeline authoring or are non-admin users, an admin must first create the connection in Catalog Explorer. See Connect to managed ingestion sources.

    • To use an existing connection, you must have USE CONNECTION privileges or ALL PRIVILEGES on the connection object.

    • You must have USE CATALOG privileges on the target catalog.

    • You must have USE SCHEMA and CREATE TABLE privileges on an existing schema or CREATE SCHEMA privileges on the target catalog.

  • To ingest from Akamai, first configure authentication from Databricks and create a connection. See Configure authentication to Akamai and Create an Akamai WAF connection.

Connector options​

The Akamai WAF connector option is table-level. Set it in connector_options.akamai_options on the table object in your pipeline definition. See Examples for usage.

Option

Required

Applies to

Description

config_ids

Yes

akamai_waf_events

The Web Security Configuration IDs whose SIEM events to ingest. Provide 1 to 1,000 numeric IDs. You can get these values from Fetch Web Security Configuration IDs.

Option

Required

Applies to

Description

config_ids

Yes

akamai_waf_events

The Web Security Configuration IDs whose SIEM events to ingest. Provide 1 to 1,000 numeric IDs. You can get these values from Fetch Web Security Configuration IDs.

Create an ingestion pipeline​

For the list of supported source tables, see Supported source tables.

Use Declarative Automation Bundles to manage Akamai WAF pipelines as code. Bundles can contain YAML definitions of jobs and tasks, are managed using the Databricks CLI, and can be shared and run in different target workspaces (such as development, staging, and production). For more information, see What are Declarative Automation Bundles?.

  1. Create a bundle using the Databricks CLI:

    Bash
    databricks bundle init
  2. Add two new resource files to the bundle:

    • A pipeline definition file (for example, resources/akamai_waf_pipeline.yml). See pipeline.ingestion_definition and Examples.
    • A job definition file that controls the frequency of data ingestion (for example, resources/akamai_waf_job.yml). Schedule the job to run at least every 12 hours.
  3. Deploy the pipeline using the Databricks CLI:

    Bash
    databricks bundle deploy

Examples​

The Akamai WAF connector makes available 1 source table in the default source schema. Ingest that table and set config_ids on the table object.

Ingest specific tables​

Use this option to customize destination naming for the table.

The following pipeline definition file ingests the Akamai WAF table:

YAML
resources:
pipelines:
akamai_waf_pipeline:
name: akamai_waf_pipeline
catalog: 'main'
target: 'akamai_waf_data'
ingestion_definition:
connection_name: akamai_waf_connection
objects:
- table:
source_schema: 'default'
source_table: 'akamai_waf_events'
destination_catalog: 'main'
destination_schema: 'akamai_waf_data'
destination_table: 'akamai_waf_events'
connector_options:
akamai_options:
config_ids:
- 12345
- 67890

Declarative Automation Bundles job definition file​

The following is an example job definition file for use with Declarative Automation Bundles. The job runs every 12 hours.

YAML
resources:
jobs:
akamai_waf_job:
name: akamai_waf_job
schedule:
quartz_cron_expression: '0 0 0/12 * * ?'
timezone_id: 'UTC'
tasks:
- task_key: akamai_waf_ingestion
pipeline_task:
pipeline_id: ${resources.pipelines.akamai_waf_pipeline.id}

Common patterns​

For advanced pipeline configurations, see Common patterns for managed ingestion pipelines.

Next steps​

Start, schedule, and set alerts on your pipeline. See Common pipeline maintenance tasks.

Additional resources​