Skip to main content

Configure authentication to Akamai

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Akamai WAF from the Previews page. See Manage Databricks previews.

Configure Akamai to enable authentication from Databricks for the Akamai WAF connector. The connector reads events from the Akamai Security Information and Event Management (SIEM) API. Use the credentials from these steps to create a Unity Catalog connection in Databricks.

Prerequisites​

  • Have an Akamai Control Center administrator enable SIEM Integration and provision the SIEM user.
  • Assign the Manage SIEM role to the user associated with the API credentials for every group containing a security configuration you want to ingest. See Akamai SIEM Integration.
  • Turn on SIEM Integration and data collection for each security configuration, and activate the configuration on the production network. See Get started with the SIEM Integration API.

Configure Akamai​

Configure Akamai to enable authentication from Databricks.

Fetch Web Security Configuration IDs​

  1. Sign in to Akamai Control Center as an Admin.
  2. Click the menu icon in the top left of the page to open the navigation pane.
  3. In the navigation pane, click Your Services > Web & Data Center Security > Security Configurations > Web Security.
  4. Review the list of security configurations. Each configuration has a dropdown. Note the Contract and Group ID under the dropdown. You need these values when you create a user with the MANAGE_SIEM role.
  5. For each security configuration that you want to ingest logs for:
    1. Click the version under Last Created, Staging, or Production.
    2. Go to Advanced Settings > Logging > Data Collection For SIEM integration > Web Security Configuration ID.
    3. Note the Web Security Configuration ID. You need these values when you create a user with the MANAGE_SIEM role.

Create a user with the MANAGE_SIEM role​

  1. Sign in to Akamai Control Center as an Admin.
  2. Click the menu icon in the top left of the page to open the navigation pane.
  3. In the navigation pane, click Your Services > Account Admin > Identity & Access.
  4. Click Create User.
  5. Enter the Email and Verify email values.
  6. Under Assign roles, select MANAGE_SIEM for each of the groups used to define the Web Security Configuration IDs from the previous step.

Create an API client​

  1. Sign in to Akamai Control Center as the user you created in the previous step.
  2. Click the menu icon in the top left of the page to open the navigation pane.
  3. In the navigation pane, click Your Services > Account Admin > Identity & Access.
  4. Click Create API Client > Advanced.
  5. Under APIs, select Select APIs.
  6. Click Reset API selection.
  7. Search for the SIEM API.
  8. Under Access level, select READ-ONLY, then click Submit.
  9. Enter a unique Name for the API client, then click Create API Client.
  10. Copy the client_secret, host, access_token, and client_token values. Akamai shows these credentials only once. Use them to create a Unity Catalog connection in Databricks.

Next steps​

Create a Akamai WAF connection in Databricks. See Create an Akamai WAF connection.