<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: (Beta) Proofpoint Email Security App for Splunk content returns no results in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293946#M35123</link>
    <description>&lt;P&gt;Thank you so much. It's a big help. I have been searching for days to resolve this issue.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Feb 2019 15:23:22 GMT</pubDate>
    <dc:creator>vnguyen46</dc:creator>
    <dc:date>2019-02-06T15:23:22Z</dc:date>
    <item>
      <title>(Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293936#M35113</link>
      <description>&lt;P&gt;This isn't a question but a post to help point out a reason you may not be seeing content in your reports or dashboards using the (Beta) Proofpoint Email Security App for Splunk. It has to do with a macro used at the beginning of each search in order to set the index. You must change the macro to point to the index where your Proofpoint data (pps__log) is.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 14:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293936#M35113</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2017-10-11T14:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293937#M35114</link>
      <description>&lt;P&gt;To change the macro open up Settings--&amp;gt;Advanced Search--&amp;gt;Search macros. Go to the app context "Proofpoint Email Security App for Splunk". There is a macro labeled get_pps_index. The macro is set to explicitly point to index=main. Since it is unlikely you are sending all of your Proofpoint data to "main" you should open this macro and change it to the index where your PPS data is sent.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293937#M35114</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2020-09-29T16:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293938#M35115</link>
      <description>&lt;P&gt;Thanks for documenting this for others!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 16:47:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293938#M35115</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2017-10-16T16:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293939#M35116</link>
      <description>&lt;P&gt;I've done that and I'm still not getting data. Plus there is little to no documentation for this app. &lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 20:41:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293939#M35116</guid>
      <dc:creator>jrsanders</dc:creator>
      <dc:date>2018-02-01T20:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293940#M35117</link>
      <description>&lt;P&gt;Have you been able to verify you have data coming in? Can you confirm all the steps you have done so far?&lt;/P&gt;

&lt;P&gt;The app setup is fairly well documented here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3080/#/details"&gt;https://splunkbase.splunk.com/app/3080/#/details&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We need to determine if this is a sourcetype issue or some other problem.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 20:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293940#M35117</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-02-01T20:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293941#M35118</link>
      <description>&lt;P&gt;Nevermind. I figured it out. I needed to add the Add-on to my indexer as well. &lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293941#M35118</guid>
      <dc:creator>jrsanders</dc:creator>
      <dc:date>2018-02-01T21:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293942#M35119</link>
      <description>&lt;P&gt;Could you tell me more about your deployment? Most deployments should not need this installed on an indexer.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:02:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293942#M35119</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-02-01T21:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293943#M35120</link>
      <description>&lt;P&gt;Our deployment consist of One Search Head and One Indexer. Our Proofpoint servers send their logs directly to the indexer. &lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293943#M35120</guid>
      <dc:creator>jrsanders</dc:creator>
      <dc:date>2018-02-01T21:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293944#M35121</link>
      <description>&lt;P&gt;Ok, that explains why. The TA's should normally go on a heavy forwarder and if you are not using one, they would have to go on your indexer.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:41:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293944#M35121</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-02-01T21:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293945#M35122</link>
      <description>&lt;P&gt;Thank you for the input. Sorry about my earlier comment. I was venting a little. &lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:43:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293945#M35122</guid>
      <dc:creator>jrsanders</dc:creator>
      <dc:date>2018-02-01T21:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: (Beta) Proofpoint Email Security App for Splunk content returns no results</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293946#M35123</link>
      <description>&lt;P&gt;Thank you so much. It's a big help. I have been searching for days to resolve this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 15:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Beta-Proofpoint-Email-Security-App-for-Splunk-content-returns-no/m-p/293946#M35123</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2019-02-06T15:23:22Z</dc:date>
    </item>
  </channel>
</rss>

