Skip to content

Akamai Enterprise Application Access

You can integrate Akamai Enterprise Application Access (EAA) with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Akamai EAA product overview

Akamai Enterprise Application Access (EAA) is a Zero Trust Network Access (ZTNA) service that provides least-privilege, per-application access based on user identity, context, and device posture, without granting network-level access, delivered from Akamai's globally distributed cloud.

What we ingest

Sophos XDR collects Akamai EAA events using the Akamai Unified Log Streamer (ULS), which forwards events as JSON over syslog to a Sophos XDR data collector. The following log categories are collected:

  • Application access: EAA per-application access events.
  • Administrative and authentication: EAA administrative and authentication events.

Event and data types

We ingest the following event and data types from Akamai EAA:

  • Application access: EAA per-application access transactions, including the user, application, URL, and result. Normalized to HTTP telemetry.
  • Administrative and authentication: EAA administrative and authentication events, including the user and action. Normalized to authentication telemetry.

Data provided by this integration

Data provided by Akamai EAA gets normalized to the following schemas:

  • auth
  • http

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation