<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to I retrieve proofpoint data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711300#M117516</link>
    <description>&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 18:08:54 GMT</pubDate>
    <dc:creator>danielbb</dc:creator>
    <dc:date>2025-02-11T18:08:54Z</dc:date>
    <item>
      <title>How to I retrieve proofpoint data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/710509#M117359</link>
      <description>&lt;P&gt;Looking at Splunk base, and there are quite a lot of Proofpoint apps/TAs, which one should I install in order to connect to the Proofpoint endpoint and receive the data?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 16:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/710509#M117359</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-02-03T16:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to I retrieve proofpoint data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/710510#M117360</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196884"&gt;@danielbb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;there are many ProofPoint modules and many ways to take logs (syslogs, scripts, etc...)&lt;/P&gt;&lt;P&gt;see here to be guided:&amp;nbsp;&lt;A href="https://www.proofpoint.com/us/partners/splunk" target="_blank"&gt;https://www.proofpoint.com/us/partners/splunk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 16:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/710510#M117360</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-03T16:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to I retrieve proofpoint data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711204#M117491</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;. Our Proofpoint account manager said the following -&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;EM&gt;"There is an API but no mail flow API so Splunk wouldn't have anything on the Essentials side. Enterprise side - Remote Syslog gets them all sorts of mail flow details!&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;nbsp;Having said that, the only way to get an integration with Splunk would be to upgrade from Essentials to our Enterprise email."&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;Is there a way to get the Proofpoint data without an upgrade?&lt;/DIV&gt;</description>
      <pubDate>Mon, 10 Feb 2025 18:26:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711204#M117491</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-02-10T18:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to I retrieve proofpoint data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711233#M117498</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/196884"&gt;@danielbb&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I don't think it's possible with that ProofPoint, due to a problem at the source of it.&lt;BR /&gt;I have integrated many ProofPoints, but honestly I couldn't tell you what version or type of PP there was.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 07:20:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711233#M117498</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-02-11T07:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to I retrieve proofpoint data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711242#M117500</link>
      <description>&lt;P&gt;Proofpoint Essentials is - as far as I remember - a simplified Proofpoint on Demand service.&lt;/P&gt;&lt;P&gt;Proofpoint Enterprise can be deployed as either Proofpoint-managed Proofpoint on Demand service or an on-premise Proofpoint Protection Server installation.&lt;/P&gt;&lt;P&gt;As I understand, you're using Essentials so you're not interested in an on-premise installation. So your only way to get the detailed email flow info would be to upgrade to Enterprise and license the Remote Syslog Forwarding feature. Then you can set up your own TLS-secured "syslog" receiver and push the events from your PoD instance.&lt;/P&gt;&lt;P&gt;Essentials is a simplified service for small businesses and therefore doesn't have all the bells and whistles that "full" Enterprise setup has. But is way cheaper as I remember.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 09:24:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711242#M117500</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-02-11T09:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to I retrieve proofpoint data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711298#M117515</link>
      <description>&lt;P&gt;Thank you Rick for the information!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 18:08:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711298#M117515</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-02-11T18:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to I retrieve proofpoint data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711300#M117516</link>
      <description>&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 18:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-I-retrieve-proofpoint-data/m-p/711300#M117516</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2025-02-11T18:08:54Z</dc:date>
    </item>
  </channel>
</rss>

