Akamai Enterprise Application Access
You can integrate Akamai Enterprise Application Access (EAA) with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Akamai EAA product overview
Akamai Enterprise Application Access (EAA) is a Zero Trust Network Access (ZTNA) service that provides least-privilege, per-application access based on user identity, context, and device posture, without granting network-level access, delivered from Akamai's globally distributed cloud.
What we ingest
Sophos XDR collects Akamai EAA events using the Akamai Unified Log Streamer (ULS), which forwards events as JSON over syslog to a Sophos XDR data collector. The following log categories are collected:
- Application access: EAA per-application access events.
- Administrative and authentication: EAA administrative and authentication events.
Event and data types
We ingest the following event and data types from Akamai EAA:
- Application access: EAA per-application access transactions, including the user, application, URL, and result. Normalized to HTTP telemetry.
- Administrative and authentication: EAA administrative and authentication events, including the user and action. Normalized to authentication telemetry.
Data provided by this integration
Data provided by Akamai EAA gets normalized to the following schemas:
authhttp
For more information about using schemas in Data Lake Search, see Schemas and logical types.