<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263516#M50562</link>
    <description>&lt;P&gt;After finally getting the infra set up to receive the TLS encrypted syslogs.... ran into some serious issues with their TA_PPS app.  Support engaged.  Waiting on response for what's next or a new release. &lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2016 23:22:29 GMT</pubDate>
    <dc:creator>ChrisBell04</dc:creator>
    <dc:date>2016-11-18T23:22:29Z</dc:date>
    <item>
      <title>How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263511#M50557</link>
      <description>&lt;P&gt;Has anyone done Splunk and Proofpoint Cloud instance integration? I am looking for help to pull the logs from Proofpoint via APIs or any other methods from the Proofpoint cloud instance. &lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 21:58:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263511#M50557</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-05-24T21:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263512#M50558</link>
      <description>&lt;P&gt;Was anyone able to figure this out yet? &lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2016 22:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263512#M50558</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-06-24T22:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263513#M50559</link>
      <description>&lt;P&gt;Proofpoint POD has an additional license "remote syslog forwarding" one can purchase to send logs from the cloud to onprem via TLS syslog stream.  Then their TA &lt;A href="https://splunkbase.splunk.com/app/3080/"&gt;https://splunkbase.splunk.com/app/3080/&lt;/A&gt; can be utilized. &lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2016 17:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263513#M50559</guid>
      <dc:creator>ChrisBell04</dc:creator>
      <dc:date>2016-06-26T17:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263514#M50560</link>
      <description>&lt;P&gt;I finally got a call from them and that's exactly what they said. &lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2016 23:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263514#M50560</guid>
      <dc:creator>daniel_augustyn</dc:creator>
      <dc:date>2016-06-29T23:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263515#M50561</link>
      <description>&lt;P&gt;Alternatively, if you're only looking for the threat data from their Targeted Attack Protection service, there's the following APIs:&lt;BR /&gt;
&lt;A href="https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API"&gt;https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Campaign_API"&gt;https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Campaign_API&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Forensics_API"&gt;https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/Forensics_API&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 23:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263515#M50561</guid>
      <dc:creator>bthommes</dc:creator>
      <dc:date>2016-11-18T23:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263516#M50562</link>
      <description>&lt;P&gt;After finally getting the infra set up to receive the TLS encrypted syslogs.... ran into some serious issues with their TA_PPS app.  Support engaged.  Waiting on response for what's next or a new release. &lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 23:22:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263516#M50562</guid>
      <dc:creator>ChrisBell04</dc:creator>
      <dc:date>2016-11-18T23:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263517#M50563</link>
      <description>&lt;P&gt;literally the worst.. can't believe it's not API driven.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 22:50:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263517#M50563</guid>
      <dc:creator>awurster</dc:creator>
      <dc:date>2016-11-28T22:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263518#M50564</link>
      <description>&lt;P&gt;Those APIs are handy, but wont provide the granular details for every message/filter/rules/policy routes/sender/host/message IDs/etc which are &lt;STRONG&gt;not originally&lt;/STRONG&gt; identified as a threat.  IMO, only the "filter" and "MTA" syslog streams have this detailed level of info.   This also gets around Proofpoint POD ~7 min smart search indexing delay, as splunk is near real time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;

&lt;P&gt;The Proofpoint case is progressing. They're meeting with Splunk engineers this week to enhanced their TA_PPS app. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 00:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263518#M50564</guid>
      <dc:creator>ChrisBell04</dc:creator>
      <dc:date>2016-11-29T00:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263519#M50565</link>
      <description>&lt;P&gt;will believe it when i see it.  API being handy is debatable, since it only shows blocked stuff.  and it's pretty limited in how you can query it versus other services i've worked with.&lt;/P&gt;

&lt;P&gt;we no longer use TAs natively in splunk, so we write all our ingestion in lambda first.  i'll post my code here when done.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 01:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263519#M50565</guid>
      <dc:creator>awurster</dc:creator>
      <dc:date>2016-11-29T01:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263520#M50566</link>
      <description>&lt;P&gt;how did you overcome requirement for PFS in the tls cipher?  Did you use an intermediary syslog server?   or adjust the splunk TCP ssl input encryption cipher? &lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 22:30:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263520#M50566</guid>
      <dc:creator>JimGat_SSI</dc:creator>
      <dc:date>2016-11-29T22:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263521#M50567</link>
      <description>&lt;P&gt;Logs flow to an intermediate RedHat server running rsyslog (which this version only supports up to TLS 1.1, but still can receive the logs from POD).  Splunk UF picks up the syslog files and forwards onto the indexers. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2016 22:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263521#M50567</guid>
      <dc:creator>ChrisBell04</dc:creator>
      <dc:date>2016-11-29T22:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263522#M50568</link>
      <description>&lt;P&gt;As identified, Secure syslog is supported and following guidance from Splunk we utilized a intermediary syslog server with syslog-ng before forwarding to a Splunk Indexer.&lt;BR /&gt;&lt;BR /&gt;
The TA is not needed, fairly straight forward to construct your own parser for the MTA log information. Have not used the APIs yet for the threat information, but will be valuable to have alongside the raw MTA information.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 14:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263522#M50568</guid>
      <dc:creator>MattSmith129</dc:creator>
      <dc:date>2017-07-20T14:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263523#M50569</link>
      <description>&lt;P&gt;Hi @awurster! Did you get a chance to work on this?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 20:42:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263523#M50569</guid>
      <dc:creator>amalkapuram</dc:creator>
      <dc:date>2017-08-14T20:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263524#M50570</link>
      <description>&lt;P&gt;I will try and post it soon, but yes it's working currently.  I'd prefer however to rewrite it for docker and clean it up a bit before publishing.&lt;/P&gt;

&lt;P&gt;Here's the snippet which is mostly working code.  Haven't really cleaned / tested it much, so YMMV.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://bitbucket.org/snippets/asecurityteam/xLpqgr"&gt;https://bitbucket.org/snippets/asecurityteam/xLpqgr&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 21:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263524#M50570</guid>
      <dc:creator>awurster</dc:creator>
      <dc:date>2017-08-15T21:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263525#M50571</link>
      <description>&lt;P&gt;Hello folks,&lt;/P&gt;

&lt;P&gt;Proofpoint now has a beta app that will allow you report on and visualze your Proofpoint Protection Server and TAP data! Check out the new app here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3727/#/details"&gt;https://splunkbase.splunk.com/app/3727/#/details&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Be sure to follow the instructions listed in the details to get all the needed TA's etc that the app needs to work correctly.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 21:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263525#M50571</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2017-10-09T21:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263526#M50572</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;

&lt;P&gt;I'm new splunk! can you please describe the various steps involved to send Proofpoint logs to splunk via syslog  &lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 03:24:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263526#M50572</guid>
      <dc:creator>ayelala</dc:creator>
      <dc:date>2018-06-14T03:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263527#M50573</link>
      <description>&lt;P&gt;Point taken. We are moving to an API driven TA and app for our next release. Look for the beta to come our around .Conf18&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 17:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263527#M50573</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-08-29T17:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263528#M50574</link>
      <description>&lt;P&gt;If you ingest the filter logs from your Protection server with remote syslog, you can see every action taken on all messages. &lt;/P&gt;

&lt;P&gt;You are correct that the TAP data is a more limited set and includes 4 eventTypes: messagesBlocked messagesDelivered clicksPermitted clicksBlocked&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 17:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263528#M50574</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-08-29T17:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263529#M50575</link>
      <description>&lt;P&gt;Please follow this guide:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3727/#/details"&gt;https://splunkbase.splunk.com/app/3727/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 17:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/263529#M50575</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-08-29T17:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to pull logs into Splunk from Proofpoint via APIs or any other methods from a Proofpoint Cloud instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/553692#M91793</link>
      <description>&lt;P&gt;Hi Chris,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can u assist with the steps (troubleshooting efforts) you have taken to integrate the proofpoint cloud logs&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 07:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-pull-logs-into-Splunk-from-Proofpoint-via-APIs-or-any/m-p/553692#M91793</guid>
      <dc:creator>santoshneelam</dc:creator>
      <dc:date>2021-05-31T07:45:15Z</dc:date>
    </item>
  </channel>
</rss>

