> For the complete documentation index, see [llms.txt](https://docs.onum.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.onum.com/listeners/listener-integrations/pull-data-from-http-endpoints/pull-data-from-akamai-apis/pull-data-from-the-akamai-siem-integration-api.md).

# Pull data from the Akamai SIEM Integration API

## Overview

Get a list of Akamai SIEM Integration security events through the [SIEM Integration API](https://techdocs.akamai.com/siem-integration/reference/api) using the **HTTP Pull** Listener.

## HTTP Pull Listener configuration

In Falcon Onum, go to the **Listeners** area and click **New Listener > HTTP Pull**. Give a name to your new Listener and enter the following data:

### Parameters

Add the following parameters:

* **Name** - `domain`
* **Integration** - Enter your Akamai SIEM Integration domain name.
* **Name** - `configId`
* **Value** - Enter your Akamai SIEM Integration configuration ID.

### Secrets

You must define these credentials in Onum:

* `clientSecret` will reference your Akamai SIEM Integration Client Secret.
* `accessToken` will reference your Akamai SIEM Integration Access Token.
* `clientToken` will reference your Akamai SIEM Integration Client Token.

To do it, click **Add element** and enter a **Name** for the secret (in this case, `clientSecret`). Then, click the **Value** field and select **New secret** to create a new one:

* Give the secret a **Name**.
* Turn off the **Expiration date** option.
* Click **Add new value** and paste the secret corresponding to the value.
* Click **Save**.

You can now select the secret you just created in the **Value** field list. Repeat the process for the `accessToken` and the `clientToken`.

{% hint style="info" %}
Learn more about secrets in Onum in [this article](/settings/organization-settings/secrets-management.md).
{% endhint %}

### Setup

After entering the required parameters and secrets, you can choose to manually enter the rest of configuration fields, or simply paste the given YAML:

{% tabs %}
{% tab title="Config as YAML" %}
Toggle **ON** the **Config as YAML** option to enable a free text field where you can paste the following YAML:

```yaml
withTemporalWindow: true
temporalWindow:
  duration: 30m
  offset: 30m
  tz: UTC
  format: Epoch
withAuthentication: true
authentication:
  type: akamai
  akamai:
    clientSecret: ${secrets.clientSecret}
    accessToken: ${secrets.accessToken}
    clientToken: ${secrets.clientToken}
withEnumerationPhase: false
collectionPhase:
  paginationType: "cursor"
  cursorSelector: .offset
  initialRequest:
    responseType: ndjson
    method: "GET"
    url: "https://${parameters.domain}/siem/v1/configs/${parameters.configId}"
    queryParams:
      - name: from
        value: ${temporalWindow.from}
      - name: to
        value: ${temporalWindow.to}
      - name: limit
        value: "1000"
  nextRequest:
    responseType: ndjson
    method: "GET"
    url: "https://${parameters.domain}/siem/v1/configs/${parameters.configId}"
    queryParams:
      - name: offset
        value: ${pagination.cursor}
      - name: limit
        value: "1000"
  output:
    select: "."
    filter: ".offset == null"
    outputMode: "element"
```

{% endtab %}

{% tab title="Manually configure" %}
**Temporal Window**

Toggle **ON** to add a temporal window for events. This repeatedly shifts the time window over which data is collected.

* **Duration**<mark style="color:$primary;">**\***</mark> - `30m`
* **Offset**<mark style="color:$primary;">**\***</mark> - `30m`
* **Format**<mark style="color:$primary;">**\***</mark> - `RFC3339`

**Authentication**

Toggle **ON** to configure the authentication phase. This is required to get the token to pull data using **OAuth**.

* **Type**<mark style="color:red;">**\***</mark> - `Akamai EdgeGrid`
* **Akamai EdgeGrid Authentication**
  * **Client Token**<mark style="color:$primary;">**\***</mark> - Enter your Client Token.
  * **Access Token**<mark style="color:$primary;">**\***</mark> - Enter your Access Token.
  * **Client Secret**<mark style="color:$primary;">**\***</mark> - Enter your Client Secret.

**Collection Phase**&#x20;

* **Pagination Type**<mark style="color:red;">**\***</mark> - `Cursor`
* **Cursor Selector**<mark style="color:$primary;">**\***</mark> - `.offset`
* **Initial Request**&#x20;
  * **Response Type**<mark style="color:$primary;">**\***</mark> - `NDJSON`
  * **Method**<mark style="color:red;">**\***</mark> - `GET`
  * **URL**<mark style="color:red;">**\***</mark> - `https://${parameters.domain}/siem/v1/configs/${parameters.configId}`
  * **Query Params**
    * **Name** - `from`
    * **Value** - `${temporalWindow.from}`
    * **Name** - `to`
    * **Value** - `${temporalWindow.to}`
    * **Name** - `limit`
    * **Value** - `1000`
* **Next Request**&#x20;
  * **Response Type**<mark style="color:$primary;">**\***</mark> - `NDJSON`
  * **Method**<mark style="color:red;">**\***</mark> - `GET`
  * **URL**<mark style="color:red;">**\***</mark> - `https://${parameters.domain}/siem/v1/configs/${parameters.configId}`
  * **Query Params**
    * **Name** - `offset`
    * **Value** - `${pagination.cursor}`
    * **Name** - `limit`
    * **Value** - `1000`
* **Output**&#x20;
  * **Select**<mark style="color:$primary;">**\***</mark> - `.`
  * **Filter** - `.offset == null`
  * **Output Mode**<mark style="color:$primary;">**\***</mark> - `element`
    {% endtab %}
    {% endtabs %}

When you're done, click **Create labels** to move on to the next step and define the required [Labels](/listeners/labels.md) if needed.
