Akamai WAF Capture Guide For Unified aiFObserve
Best Capture Source
Use Akamai SIEM/security event export for Kona Site Defender, App & API Protector, or related Akamai WAF services. Export security events in JSON or a structured CSV created from the JSON fields.
Basic Logging
Capture these fields when available:
- event timestamp
- request ID or event ID
- client IP
- client port
- host
- URL or path
- request method
- HTTP status
- user agent
- policy ID or policy name
- rule ID, rule message, rule tag
- action or disposition
- attack data
- request headers needed for host, user, and trace correlation
Extended Logging
For full-scale analysis, keep:
- security configuration ID
- policy version
- rule set and rule group
- attack category
- matched data or matched variable, sanitized as needed
- reputation score or risk score
- edge location or network context
- account/contract/group/property identifiers
- API endpoint, API ID, or route metadata when protecting AI APIs
- request and response size fields when available from delivery/access logs
User And App Identity
Best identity signals:
- authenticated identity header from upstream identity-aware services
- host, path, API endpoint, property name
- account/contract/group/property IDs
- user agent
For richer identity, export WAF events together with delivery/access logs or application logs and preserve request IDs for correlation.
AI Provider And Location Evidence
Keep edge location, host, origin/backend, property ID, and account context. These fields help compliance reports explain where AI/API traffic was observed.