Akamai WAF
Use the Akamai WAF integration to manage common sets of lists used by various Akamai security products and features. This is the modified version where a new command "akamai-update-network-list-elements" was added by the SA.
- Category
- Network Security
- Pack
- Akamai_WAF
Configuration parameters
- host — Server URL (e.g., https://example.net) (required)
- clientToken — Client token
- accessToken — Access token
- clientSecret — Client secret
- credentials_client_token —
- credentials_access_token —
- credentials_client_secret —
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (92)
- akamai-acknowledge-pre-verification-warning — acknowledge pre verification warning.
- akamai-acknowledge-warning-command — Acknowledge the warning message for uploading the certs and trust chains of enrollments.
- akamai-activate-appsec-config-version — AppSec activate appsec configuration version.
- akamai-activate-client-list — Activates a client list.
- akamai-activate-network-list — Deprecated. Use “akamai-activate-client-list” instead.
- akamai-activate-papi-property — Activate a PAPI property.
- akamai-add-client-list-entry — Adds one or more entries to a client list.
- akamai-add-elements-to-network-list — Deprecated. Use “akamai-add-client-list-entry” instead.
- akamai-add-papi-property-hostname — Add hostnames to the PAPI property.
- akamai-cancel-cps-change — Cancels a pending change on CPS.
- akamai-check-group — Check an existing group within the context of your account.
- akamai-clone-appsec-config-version — AppSec_clone appsec config version.
- akamai-clone-papi-property — Clone a new PAPI property.
- akamai-clone-security-policy — AppSec clone security policy.
- akamai-create-client-list — Creates a new client list.
- akamai-create-datacenter — Create a data center.
- akamai-create-domain — Create a domain with properties and domain controller (DC).
- akamai-create-enrollment — Create a new enrollment.
- akamai-create-group — Create a new group under a parent GID.
- akamai-create-network-list — Deprecated. Use “akamai-create-client-list” instead.
- akamai-deactivate-client-list — Deactivates a client list.
- akamai-delete-datastream — Deletes a deactivated stream. Deleting a stream means that you can't activate this stream again, and that you stop receiving logs for the properties that this stream monitors. Before deleting any stream, you need to deactivate it first. See Deactivate a stream.
- akamai-delete-network-list — Deprecated. Use “akamai-deprecate-client-list” instead.
- akamai-deprecate-client-list — Deprecates a client list.
- akamai-generic-api-call-command — Akamai Generic API Call.
- akamai-get-appsec-config-activation-status — AppSec get appsec config activation status.
- akamai-get-appsec-config-latest-version — AppSec get appsec config latest version.
- akamai-get-change — Get the CPS code.
- akamai-get-change-history — Get change history.
- akamai-get-client-list — Get a client list.
- akamai-get-client_lists — Get accessible client lists.
- akamai-get-contract-group — Get contract groups.
- akamai-get-cps-change-status — Gets the status of a pending change.
- akamai-get-cps-enrollment-by-id — Get an enrollment in CPS by enrollment id.
- akamai-get-cps-enrollment-deployment — Returns the certification/enrollment deployment status for specific a environment: production or staging.
- akamai-get-cps-enrollmentid-by-cnname — Get cps certificate enrollment ID by common name.
- akamai-get-datastream — Returns information about any version of a stream, including details about the monitored properties, logged data set fields, and log delivery destination. If you omit the version query parameter, this operation returns the last version of the stream.
- akamai-get-domain — Get a specific GTM domain.
- akamai-get-domains — Get Google Tag Manager (GTM) domains.
- akamai-get-enrollment-by-cn — Get enrollment by common name.
- akamai-get-group — Get group.
- akamai-get-network-list-activation-status — Deprecated. There is no replacement for this command.
- akamai-get-network-list-by-id — Deprecated. Use “akamai-get-client-list” instead.
- akamai-get-network-lists — Deprecated. Use “akamai-get-client-list” instead.
- akamai-get-papi-edgehostname-creation-status-command — Get PAPI edgehostname creation status command until it is created.
- akamai-get-papi-property-activation-status-command — Get PAPI property activation status until it is active.
- akamai-get-papi-property-by-id — get papi property info by id without default rule. to get default rule, please use "get-papi-property-rule" command.
- akamai-get-papi-property-by-name — Get PAPI property info without the default rule. To get the default rule, use the "get-papi-property-rule" command.
- akamai-get-papi-property-rule — get papi property rule json and dump into string.
- akamai-get-production-deployment — Get Production Deployment.
- akamai-get-security-policy-id-by-name — AppSec get security policy ID by name.
- akamai-list-appsec-config — Lists available security configurations. Products: All.
- akamai-list-appsec-configuration-activation-history — Lists the activation history for a configuration. The history is an array in descending order of submitDate. The most recent submitted activation lists first. Products: All.
- akamai-list-cidr-blocks — List all CIDR blocks for all services you are subscribed to. To see additional CIDR blocks, subscribe yourself to more services and run this operation again.
- akamai-list-cps-active-certificates — Lists enrollments with active certificates. Note that the rate limit for this operation is 10 requests per minute per account.
- akamai-list-datastream-groups — Returns access groups with contracts on your account. You can later use the groupId and contractId values to create and view streams or list properties by group. Set the contractId query parameter to get groups for a specific contract.
- akamai-list-datastream-properties-bygroup — Get properties that are active on the production and staging network and available within a specific group. Run this operation to get and store the propertyId values for the Create a stream and Edit a stream operations.
- akamai-list-datastreams — Returns the latest versions of the stream configurations for all groups within the account.
- akamai-list-dns-zone-recordsets — Lists all record sets for this zone. It works only for PRIMARY and SECONDARY zones.
- akamai-list-dns-zones — List all zones that the current user has access to manage.
- akamai-list-edgehostname — Lists all edge hostnames available under a contract.
- akamai-list-enrollments — List enrollments of a specific contract.
- akamai-list-groups — Lists groups of Akamai.
- akamai-list-idam-properties — Lists the properties and includes for the current account.
- akamai-list-papi-property-activations — This lists all activations for all versions of a property, on both production and staging networks.
- akamai-list-papi-property-by-group — Lists properties available for the current contract and group.
- akamai-list-papi-property-by-hostname — Lists active property hostnames for all properties available in an account.
- akamai-list-siteshield-map — Returns a list of all Site Shield maps that belong to your account.
- akamai-modify-appsec-config-selected-hosts — Update the list of selected hostnames for a configuration version.
- akamai-new-datastream — Creates a stream configuration. Within a stream configuration, you can select properties to monitor in the stream, data set fields to collect in logs, and a destination to send these log files to. Get the streamId value from the response to use in the https://{hostname}/datastream-config-api/v2/log/streams/{streamId} endpoint URL. Apart from the log and delivery frequency configurations, you can decide whether to activate the stream on making the request or later using the activate parameter. Note that only active streams collect and send logs to their destinations. NOTE: "SPLUNK" and "HTTPS" are the only two types tested.
- akamai-new-match-target — AppSec create match target.
- akamai-new-or-renew-match-target — New match target if no existing found otherwise update the existing match target hostnames. If there are multiple match targets found, the first one in the list will be updated.
- akamai-new-papi-cpcode — Create a new PAPI CP code.
- akamai-new-papi-edgehostname — Add a PAPI edge hostname.
- akamai-new-papi-property-version — Create a new property version based on any previous version. All data from the createFromVersion populates the new version, including its rules and hostnames.
- akamai-patch-datastream — Updates selected details of an existing stream. Running this operation using JSON Patch syntax creates a stream version that replaces the current one. Currently you can patch a stream using only the REPLACE operation. When updating configuration objects such as destination or deliveryConfiguration, pass a complete object to avoid overwriting current details with default values for omitted members such as tags, uploadFilePrefix, and uploadFileSuffix. Note that only active streams collect and send logs to their destinations. You need to set the activate parameter to true while patching active streams, and optionally for inactive streams if you want to activate them upon request. See Patching streams for details.
- akamai-patch-papi-property-rule-cpcode — Patch PAPI property default rule with a CP code.
- akamai-patch-papi-property-rule-generic — Generic JSON patch command for Papi Property Default Rule.
- akamai-patch-papi-property-rule-httpmethods — Patch PAPI property rule HTTP methods.
- akamai-patch-papi-property-rule-origin — Patch PAPI property default rule with an origin.
- akamai-patch-papi-property-rule-siteshield — Patch papi property default rule siteshield.
- akamai-remove-client-list-entry — Removes an entry from a client list.
- akamai-remove-element-from-network-list — Deprecated. Use “akamai-remove-client-list-entry” instead.
- akamai-toggle-datastream — Activate/Deactivate the latest version of a DataStream.
- akamai-update-appsec-config-version-notes — Update application secuirty configuration version notes command.
- akamai-update-change — Update the certs and trust chains.
- akamai-update-client-list — Updates a client list.
- akamai-update-client-list-entry — Updates an entry in a client list.
- akamai-update-cps-enrollment — Updates an enrollment with changes. Response type will vary depending on the type and impact of change. For example, changing SANs list may return HTTP 202 Accepted since the operation requires new certificate and network deployment operations, and thus cannot be completed without a change. On the contrary, for example a Technical Contact name change may return HTTP 200 OK assuming there are no active changes and the operation does not require a new certificate. Reference: https://techdocs.akamai.com/cps/reference/put-enrollment Note: Depending on the type of the modification, additional steps might be required to complete the update. These additional steps could be carrying out a "renew" change by resubmitting the CSR, acknowledging the warnings raised then waiting for the certificate to be deployed into Production. However, these additional steps are not included in this command. You need to perform those steps once the update command is completed.
- akamai-update-cps-enrollment-schedule — Updates the current deployment schedule.
- akamai-update-network-list-elements — Deprecated. There is no replacement for this command.
- akamai-update-property — Update a property for a specific domain.