Akamai WAF connector reference
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Akamai WAF from the Previews page. See Manage Databricks previews.
Reference information for the managed Akamai WAF connector, including the supported source table, the akamai_waf_events destination schema, and connector options.
Supported source tables
The Akamai WAF connector supports the following source table, under the default source schema:
Source table | Primary key | Description | Sync mode | Cursor field |
|---|---|---|---|---|
|
| WAF security events from the Akamai SIEM API, including attack, bot, geo, HTTP, and identity fields. | Incremental |
|
Connector options
The Akamai WAF connector supports the following table-level configuration option. Set it in connector_options.akamai_options on the table object. See Examples for usage.
Option | Type | Scope | Required | Applies to | Description |
|---|---|---|---|---|---|
| Array of integers | Table | Yes |
| Web Security Configuration IDs to ingest. Provide 1 to 1,000 IDs. |
Destination table schemas
akamai_waf_events
Primary key: _databricks_primary_key
Cursor field: time
For field definitions from Akamai, see the Akamai SIEM Integration API.
Field | Data type |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
This table does not support SCD type 2 because WAF logs are append-only.
Required Akamai account permissions
Permission | Required for |
|---|---|
Admin access in Control Center | Enable SIEM Integration, create the API client user, and collect Web Security Configuration IDs |
Manage SIEM role | Baseline access for the API client user |
SIEM API access level READ-ONLY | Fetch security events for the selected configuration IDs |