Skip to main content

Akamai WAF connector reference

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Akamai WAF from the Previews page. See Manage Databricks previews.

Reference information for the managed Akamai WAF connector, including the supported source table, the akamai_waf_events destination schema, and connector options.

Supported source tables​

The Akamai WAF connector supports the following source table, under the default source schema:

Source table

Primary key

Description

Sync mode

Cursor field

akamai_waf_events

_databricks_primary_key

WAF security events from the Akamai SIEM API, including attack, bot, geo, HTTP, and identity fields.

Incremental

time

Source table

Primary key

Description

Sync mode

Cursor field

akamai_waf_events

_databricks_primary_key

WAF security events from the Akamai SIEM API, including attack, bot, geo, HTTP, and identity fields.

Incremental

time

Connector options​

The Akamai WAF connector supports the following table-level configuration option. Set it in connector_options.akamai_options on the table object. See Examples for usage.

Option

Type

Scope

Required

Applies to

Description

config_ids

Array of integers

Table

Yes

akamai_waf_events

Web Security Configuration IDs to ingest. Provide 1 to 1,000 IDs.

Option

Type

Scope

Required

Applies to

Description

config_ids

Array of integers

Table

Yes

akamai_waf_events

Web Security Configuration IDs to ingest. Provide 1 to 1,000 IDs.

Destination table schemas​

akamai_waf_events​

Primary key: _databricks_primary_key Cursor field: time

For field definitions from Akamai, see the Akamai SIEM Integration API.

Field

Data type

_databricks_primary_key

LONG

time

TIMESTAMP

format

STRING

type

STRING

version

STRING

attackData

STRUCT

attackData.appliedAction

STRING

attackData.clientIP

STRING

attackData.configId

STRING

attackData.policyId

STRING

attackData.ruleActions

STRING

attackData.ruleData

STRING

attackData.ruleMessages

STRING

attackData.ruleSelectors

STRING

attackData.ruleTags

STRING

attackData.ruleVersions

STRING

attackData.rules

STRING

attackData.apiId

STRING

attackData.apiKey

STRING

attackData.clientReputation

STRING

attackData.slowPostAction

STRING

attackData.slowPostRate

STRING

attackData.decodedRules

ARRAY<STRUCT>

attackData.decodedRules.rule

STRING

attackData.decodedRules.ruleAction

STRING

attackData.decodedRules.ruleData

STRING

attackData.decodedRules.ruleMessage

STRING

attackData.decodedRules.ruleSelector

STRING

attackData.decodedRules.ruleTag

STRING

attackData.decodedRules.ruleVersion

STRING

botData

STRUCT

botData.botScore

STRING

botData.responseSegment

STRING

clientData

STRUCT

clientData.telemetryType

STRING

clientData.appBundleId

STRING

clientData.appVersion

STRING

clientData.sdkVersion

STRING

custom

STRING

geo

STRUCT

geo.asn

STRING

geo.city

STRING

geo.continent

STRING

geo.country

STRING

geo.regionCode

STRING

httpMessage

STRUCT

httpMessage.bytes

STRING

httpMessage.host

STRING

httpMessage.method

STRING

httpMessage.path

STRING

httpMessage.port

STRING

httpMessage.protocol

STRING

httpMessage.query

STRING

httpMessage.requestHeaders

STRING

httpMessage.requestId

STRING

httpMessage.responseHeaders

STRING

httpMessage.start

STRING

httpMessage.status

STRING

httpMessage.tls

STRING

identity

STRUCT

identity.ja4

STRING

identity.tlsFingerprintV2

STRING

identity.tlsFingerprintV3

STRING

userRiskData

STRUCT

userRiskData.allow

STRING

userRiskData.emailDomain

STRING

userRiskData.general

STRING

userRiskData.originUserId

STRING

userRiskData.risk

STRING

userRiskData.score

STRING

userRiskData.status

STRING

userRiskData.trust

STRING

userRiskData.username

STRING

userRiskData.uuid

STRING

Field

Data type

_databricks_primary_key

LONG

time

TIMESTAMP

format

STRING

type

STRING

version

STRING

attackData

STRUCT

attackData.appliedAction

STRING

attackData.clientIP

STRING

attackData.configId

STRING

attackData.policyId

STRING

attackData.ruleActions

STRING

attackData.ruleData

STRING

attackData.ruleMessages

STRING

attackData.ruleSelectors

STRING

attackData.ruleTags

STRING

attackData.ruleVersions

STRING

attackData.rules

STRING

attackData.apiId

STRING

attackData.apiKey

STRING

attackData.clientReputation

STRING

attackData.slowPostAction

STRING

attackData.slowPostRate

STRING

attackData.decodedRules

ARRAY<STRUCT>

attackData.decodedRules.rule

STRING

attackData.decodedRules.ruleAction

STRING

attackData.decodedRules.ruleData

STRING

attackData.decodedRules.ruleMessage

STRING

attackData.decodedRules.ruleSelector

STRING

attackData.decodedRules.ruleTag

STRING

attackData.decodedRules.ruleVersion

STRING

botData

STRUCT

botData.botScore

STRING

botData.responseSegment

STRING

clientData

STRUCT

clientData.telemetryType

STRING

clientData.appBundleId

STRING

clientData.appVersion

STRING

clientData.sdkVersion

STRING

custom

STRING

geo

STRUCT

geo.asn

STRING

geo.city

STRING

geo.continent

STRING

geo.country

STRING

geo.regionCode

STRING

httpMessage

STRUCT

httpMessage.bytes

STRING

httpMessage.host

STRING

httpMessage.method

STRING

httpMessage.path

STRING

httpMessage.port

STRING

httpMessage.protocol

STRING

httpMessage.query

STRING

httpMessage.requestHeaders

STRING

httpMessage.requestId

STRING

httpMessage.responseHeaders

STRING

httpMessage.start

STRING

httpMessage.status

STRING

httpMessage.tls

STRING

identity

STRUCT

identity.ja4

STRING

identity.tlsFingerprintV2

STRING

identity.tlsFingerprintV3

STRING

userRiskData

STRUCT

userRiskData.allow

STRING

userRiskData.emailDomain

STRING

userRiskData.general

STRING

userRiskData.originUserId

STRING

userRiskData.risk

STRING

userRiskData.score

STRING

userRiskData.status

STRING

userRiskData.trust

STRING

userRiskData.username

STRING

userRiskData.uuid

STRING

note

This table does not support SCD type 2 because WAF logs are append-only.

Required Akamai account permissions​

Permission

Required for

Admin access in Control Center

Enable SIEM Integration, create the API client user, and collect Web Security Configuration IDs

Manage SIEM role

Baseline access for the API client user

SIEM API access level READ-ONLY

Fetch security events for the selected configuration IDs

Permission

Required for

Admin access in Control Center

Enable SIEM Integration, create the API client user, and collect Web Security Configuration IDs

Manage SIEM role

Baseline access for the API client user

SIEM API access level READ-ONLY

Fetch security events for the selected configuration IDs