All templates

Automated Akamai Traffic Spike Alerts

Every hour, WebRun checks Akamai's security events for spikes in blocked, malicious, or bot traffic above your normal baseline, saves a copy of the event report to Google Drive, and posts an alert to Slack so your team can look before it becomes an outage.

Runs on WebRun · Strict Lockdown policy
Every hour WebRunorchestrates each step
1 Akamai watch for traffic spikes
2 Google Drive archive the event report
3 Slack alert the team
In short

How do I get alerted the moment attack traffic spikes on my Akamai properties?

WebRun checks Akamai's security events every hour for spikes in blocked, malicious, or bot traffic above baseline. When it finds one, it saves the event report to Google Drive and posts an alert to Slack naming the property and the spike size, so your team can investigate within the hour instead of finding out from a customer.

  • Traffic spikes get a Slack alert within the hour they happen, not the next morning
  • Every spike's evidence is archived automatically for later review
  • Quiet hours produce zero noise, so alerts stay meaningful

Built for security teams · site reliability engineers · IT admins · e-commerce teams

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens control.akamai.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Akamai - watch for traffic spikes
    akamai.com
    WebRun in Akamai: watch for traffic spikes
    WebRun opens Akamai to watch for traffic spikes.
    • Open Akamai and check security events for the past hour
    • Compare blocked and flagged traffic against the normal baseline
    • Note which property, rule, and traffic type triggered the spike

    Done when This hour's traffic has been checked against baseline and any spike is documented.

  3. 2
    Google Drive - archive the event report
    drive.google.com
    WebRun in Google Drive: archive the event report
    WebRun opens Google Drive to archive the event report.
    • Open the security incidents folder in Google Drive
    • Save a copy of the event report with the date and property name
    • Keep the file alongside prior reports so trends are easy to compare

    Done when This hour's event report is archived in Google Drive.

  4. 3
    Slack - alert the team
    slack.com
    WebRun in Slack: alert the team
    WebRun opens Slack to alert the team.
    • Post an alert to the security channel in Slack when traffic exceeds baseline
    • Include the property, the spike size, and a link to the archived report
    • Stay quiet when traffic is within the normal range

    Done when The team has a Slack alert for any hour that exceeded baseline, and nothing when it did not.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
control.akamai.com
ScheduleRuns automatically on this cadence
Every hour
DeliveryHow each run's result reaches you
Traffic spike alert · Slack
OutputWhat each run produces - An hourly traffic check, with a Slack alert and archived report only when blocked or malicious traffic exceeds baseline.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it message anyone outside the security team?

No. Alerts only post to your internal Slack channel. WebRun never contacts customers, visitors, or outside parties about traffic events.

Does it change any Akamai security rules or block traffic itself?

No. WebRun only reads event data and reports it. Any rule change, such as tightening a WAF policy, is left for your security team to make.

Will I get paged for normal traffic?

No. It only posts when traffic exceeds your normal baseline. Routine hours produce no alert at all.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.