Akamai

Download 5
Last updated Dec 6, 2024

akamai-security-events

Get security events from Akamai service.

akamai-security-events [profile=PROFILE] config-id=CONFIG-ID [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss] [raw=RAW]
profile=PROFILE
Akamai connect profile code
config-id=CONFIG-ID
Unique identifier for each security configuration.
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
raw=RAW
t or f. Specify 't' to output line field.

Output Fields

FieldTypeNameDescription
_timeDateTimeStart time of session
profileStringConnect profileAkamai connect profile code
config_idStringConfig IDSecurity configuration ID
req_idStringRequest IDHTTP request identifier
src_ipIP addressSource IPSource IP address
src_reputationStringSource reputatione.g. ID=222.239.104.74;WEBSCRP=10
signatureStringSignaturee.g. Scanning Tools (High Threat)
actionStringActione.g. PERMIT, DETECT, BLOCK
statusIntegerStatuse.g. 200, 403, 404, 500
methodStringMethode.g. GET, HEAD, POST, PUT, DELETE, OPTIONS, PATCH, CONNECT, TRACE
hostStringHoste.g. acme.com
dst_portIntegerDestination porte.g. 443
pathStringPathe.g. /health/check
queryStringQuery
sc_bytesLongDownload bytesBytes from server to client
http_verStringHTTP versione.g. HTTP/1.1
tlsStringTLS versione.g. tls1.3
req_headersStringHTTP request headersLine separated headers
resp_headersStringHTTP response headersLine separated headers
policy_idStringPolicy IDe.g. 0001_256272
rulesStringRulese.g. SQL-INJECTION-ANOMALY
rule_dataStringRule datae.g. Vector score: 1005, Group Threshold: 9, ...
rule_actionsStringRule actionse.g. monitor, alert, deny
rule_tagsStringRule tagse.g. AKAMAI/BOT/AKAMAI_CATEGORIZED
rule_selectorsStringRule selectorse.g. REQUEST_HEADERS:User-Agent
rule_versionsStringRule versionse.g. 1
src_continentStringSource continente.g. EU, NA, AS, SA
src_countryStringSource countrye.g. IE, US, KR, BR
src_regionStringSource regione.g. VA, SP, TX
src_cityStringSource citye.g. SEOUL, TOKYO, DUBLIN