Skip to main content

Akamai Prolexic

This Integration is part of the Akamai Prolexic Pack.#

Supported versions

Available on Cortex XSIAM.

Collects DDoS detection critical events and general events from Akamai Prolexic Analytics for Cortex XSIAM. This integration was integrated and tested with version v2 of the Akamai Prolexic Analytics API.

Configure Akamai Prolexic in Cortex#

ParameterDescriptionRequired
Server URLThe Akamai API host (the value of the "host" field in your .edgerc file). Example: https://akab-h05tnam3wl42son7nktnlnnx-kbob3i3v.luna.akamaiapis.netTrue
Contract IDThe policy domain name of the data center or proxy that the events belong to.True
Client TokenThe EdgeGrid client token, taken from the "client_token" field of your .edgerc file.True
Client SecretThe EdgeGrid client secret, taken from the "client_secret" field of your .edgerc file.True
Access TokenThe EdgeGrid access token, taken from the "access_token" field of your .edgerc file.True
Account Switch KeyThe account switch key used to run operations against a managed account, for customers managing more than one account. The Identity and Access Management API provides a list of available account switch keys.False
Trust any certificate (not secure)False
Use system proxy settingsFalse
Fetch eventsFalse
Event types to fetchThe Akamai Prolexic event sources to collect. Each selected source is fetched and deduplicated independently.True
First fetch timeThe point in time from which to start fetching events on the first run. Examples: "1 day", "12 hours".False
Maximum events per fetchThe maximum number of events to fetch per source, per fetch. Maximum allowed: 10000.False

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

akamai-prolexic-get-events#


Gets events from Akamai Prolexic. This command is used for developing and debugging and is to be used with caution, as it can create duplicate events in the dataset.

Base Command#

akamai-prolexic-get-events

Input#

Argument NameDescriptionRequired
limitThe maximum number of events to retrieve per source. Default is 50.Optional
event_typeA comma-separated list of event types to retrieve. If empty, uses the integration configuration. Possible values are: Critical Events, Events.Optional
start_timeThe lower-bound timestamp for events to retrieve. Supports ISO 8601 (e.g., "2026-04-20T10:00:00Z") or relative time expressions (e.g., "3 days ago"). If omitted, the integration's "First fetch time" value is used.Optional
end_timeThe upper-bound timestamp for events to retrieve. Supports ISO 8601 (e.g., "2026-04-20T18:00:00Z") or relative time expressions (e.g., "1 hour ago"). If omitted, no upper bound is applied.Optional
should_push_eventsWhether to push the retrieved events to Cortex XSIAM. If false, the events are only displayed. Possible values are: true, false. Default is false.Required

Context Output#

There is no context output for this command.

Command example#

!akamai-prolexic-get-events limit=2 event_type="Critical Events" should_push_events=false

Context Example#

{}

Human Readable Output#

Akamai Prolexic Events#

_timeevent_typesource_log_type_ENTRY_STATUSidfirstOccurrecentOccurseveritydescription
2026-04-20T10:00:00.000000ZCritical EventsCRITICAL_EVENTSnewce-12026-04-20T10:00:00Z2026-04-20T10:00:00ZhighDDoS detected on policy A
2026-04-20T11:30:00.000000ZCritical EventsCRITICAL_EVENTSupdatedce-22026-04-20T11:30:00Z2026-04-20T12:00:00ZcriticalVolumetric attack on policy B