Skip to main content

Troubleshoot the Akamai WAF connector

Beta

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Akamai WAF from the Previews page. See Manage Databricks previews.

Resolve common Akamai WAF connector errors, including authentication failures from invalid EdgeGrid credentials, inaccessible configuration IDs, and transient service errors.

For general troubleshooting guidance that applies to all managed ingestion pipelines, see Troubleshoot managed ingestion pipelines.

Pipeline fails to authenticate​

Cause: Akamai returned an HTTP 400 or 401 response. This usually means the host, client token, client secret, or access token isn't valid, someone revoked the API client, or the credentials expired.

Solution:

  1. Confirm that the Host, Client Token, Client Secret, and Access Token in the Unity Catalog connection match the API client in Akamai.
  2. Confirm that the Host doesn't include https:// and ends with .cloudsecurity.akamaiapis.net or .luna.akamaiapis.net.
  3. If the API client credentials expired, create a new API client and update the connection. EdgeGrid credentials expire after 2 years by default.

For details, see Configure authentication to Akamai.

Configuration IDs don't exist or aren't accessible​

Cause: Akamai returned HTTP 403 because at least one ID in config_ids doesn't exist or the API client can't access it.

Solution:

  1. Confirm each Web Security Configuration ID in config_ids matches a configuration that has SIEM Integration and data collection enabled.
  2. Confirm that the API client user has the Manage SIEM role on the groups that own those configurations.
  3. Confirm that the SIEM API client has READ-ONLY access.

For details, see Configure authentication to Akamai.

Akamai API rate limit exceeded​

Cause: Akamai returned an HTTP 429 response.

Solution:

The connector waits and retries automatically. If this happens repeatedly, reduce the number of concurrent pipelines that share the same Akamai API client. Keep the pipeline scheduled to run at least every 12 hours so you don't miss events.

Akamai API temporarily unavailable​

Cause: Akamai returned a transient server error (HTTP 500, 502, 503, or 504).

Solution:

The connector automatically retries. If the issue persists, wait, then run the pipeline again.

Destination table is missing recent events​

Cause: Akamai retains SIEM events for 12 hours. If the pipeline doesn't run inside that window, those events aren't available to ingest.

Solution:

Schedule the pipeline to run at least every 12 hours. Events older than 12 hours can't be backfilled. See Akamai WAF connector limitations.