https://catalogartifact.azureedge.net/publicartifacts/akamai-technologies.akamai_guardicore_sentinel-87843b1d-90d0-46ad-9aa4-97cfaa0b87ef/image5_akamailogo216x216square.png
Akamai Guardicore Sentinel Integration
by Akamai Technologies
Just a moment, logging you in...
Cloud and Data Center Visibility, micro-segmentation and breach detection
The Akamai Guardicore Segmentation data connector forwards security events from the Guardicore platform into Microsoft Sentinel via syslog in Common Event Format (CEF), enabling security teams to correlate microsegmentation alerts with endpoint, identity, and cloud signals in a single workspace.
What data is ingested:
- Security incidents — Hunt detections (AI-powered and analyst-driven), Policy Violations, Bad Reputation, and Deception events. Each incident includes severity, affected source and destination assets, protocol, port, asset labels, and incident tags. Process paths are included for Policy Violation and Bad Reputation events.
- Network flow events — Flow-level records (source/destination IP, port, protocol, matched policy name, and process details from the Guardicore agent) forwarded only for the time window surrounding a fired security incident Flows are deduplicated across overlapping incident windows to avoid redundant ingestion.
Key use cases:
- Detect and investigate lateral movement using Guardicore's process-level east-west traffic visibility
- Correlate segmentation policy violations with identity and endpoint signals from other Sentinel data sources
- Hunt threats across hybrid environments (data centers, cloud, containers) using structured CEF fields in KQL queries
How it works:
Guardicore exports events in CEF format over TCP or UDP syslog to a Linux-based log forwarder running the Microsoft Sentinel CEF connector, which relays events to the Log Analytics workspace. TLS-secured syslog is supported for encrypted transport. Event types (security incidents, network flows) are configurable.
Prerequisites:
- Akamai Guardicore Segmentation deployment
- A Linux syslog forwarding agent with the Microsoft Sentinel CEF connector installed
- Outbound syslog connectivity (TCP/UDP, configurable port) from the Centra deployment to the forwarder
At a glance
https://catalogartifact.azureedge.net/publicartifacts/akamai-technologies.akamai_guardicore_sentinel-87843b1d-90d0-46ad-9aa4-97cfaa0b87ef/image4_incidentsanalysis.png
https://catalogartifact.azureedge.net/publicartifacts/akamai-technologies.akamai_guardicore_sentinel-87843b1d-90d0-46ad-9aa4-97cfaa0b87ef/image1_workloadprotectiondashboard.png