<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371349#M67412</link>
    <description>&lt;P&gt;Hello Team ,&lt;/P&gt;

&lt;P&gt;we have requirement to integrete the proofpoint threat response [ TRAP] appliance logs within splunk. i have checked and gone through documentation here and it seems we have options to integrate proofpoint email gateway and tap appliances  but it seems there is no info i could find on how to integrate proofpoint Trap within spunk .&lt;/P&gt;

&lt;P&gt;Kindly help to understand this , may be what i suspect is all logs we can capture using proofpoint email gateway itself and trap integration is not required or there is way to integrate the trap appliances logs , i dont have much idea how proofpoint exactly functions which is causing more confusion&lt;/P&gt;

&lt;P&gt;Help is appreciated , currently we have proofpoint email gateway and TAP appliances and trap implemented in the organization and we are planning to integrate all 3 with splunk&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jan 2018 17:04:00 GMT</pubDate>
    <dc:creator>SunilMaharishi</dc:creator>
    <dc:date>2018-01-03T17:04:00Z</dc:date>
    <item>
      <title>Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371349#M67412</link>
      <description>&lt;P&gt;Hello Team ,&lt;/P&gt;

&lt;P&gt;we have requirement to integrete the proofpoint threat response [ TRAP] appliance logs within splunk. i have checked and gone through documentation here and it seems we have options to integrate proofpoint email gateway and tap appliances  but it seems there is no info i could find on how to integrate proofpoint Trap within spunk .&lt;/P&gt;

&lt;P&gt;Kindly help to understand this , may be what i suspect is all logs we can capture using proofpoint email gateway itself and trap integration is not required or there is way to integrate the trap appliances logs , i dont have much idea how proofpoint exactly functions which is causing more confusion&lt;/P&gt;

&lt;P&gt;Help is appreciated , currently we have proofpoint email gateway and TAP appliances and trap implemented in the organization and we are planning to integrate all 3 with splunk&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 17:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371349#M67412</guid>
      <dc:creator>SunilMaharishi</dc:creator>
      <dc:date>2018-01-03T17:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371350#M67413</link>
      <description>&lt;P&gt;There is not currently an integration with Splunk to send the TRAP logs into Splunk. We are working on adding this in a future release but do not have a firm timeline yet. &lt;/P&gt;

&lt;P&gt;You are correct, only the email gateway and TAP have an integration with Splunk currently.&lt;/P&gt;

&lt;P&gt;You can download the APP and related TA's here-&lt;/P&gt;

&lt;P&gt;App:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3727/#/details"&gt;https://splunkbase.splunk.com/app/3727/#/details&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Gateway TA:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3080/"&gt;https://splunkbase.splunk.com/app/3080/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;TAP TA:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3681/"&gt;https://splunkbase.splunk.com/app/3681/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 18:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371350#M67413</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-01-03T18:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371351#M67414</link>
      <description>&lt;P&gt;Thank you . So is integrating the gateway and tap solve the issue or trap does provide significant logs which aren't captured at email gateway end . &lt;/P&gt;

&lt;P&gt;I mean email gateway also can send quarantine email and other logs . If you have any idea will be helpful&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 19:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371351#M67414</guid>
      <dc:creator>SunilMaharishi</dc:creator>
      <dc:date>2018-01-03T19:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371352#M67415</link>
      <description>&lt;P&gt;TRAP will have just logging of incidents which are basically pulled emails related to threats. This will still only be logged in the TRAP console but you can see the TAP related events in Splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 21:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371352#M67415</guid>
      <dc:creator>eckolp2003</dc:creator>
      <dc:date>2018-01-03T21:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371353#M67416</link>
      <description>&lt;P&gt;I know this is a very old thread, but I'm looking for a proofpoint TRAP add-on for Splunk. I see that the data can come in via syslog, but I'm concerned about field extractions. Is there one yet, or is there documentation for it yet?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371353#M67416</guid>
      <dc:creator>manderson7</dc:creator>
      <dc:date>2019-03-20T14:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371354#M67417</link>
      <description>&lt;P&gt;I am also looking for this, Any updates from Proofpoint on this one?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 18:20:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371354#M67417</guid>
      <dc:creator>skyelowryvancit</dc:creator>
      <dc:date>2019-10-31T18:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371355#M67418</link>
      <description>&lt;P&gt;Same here... Looking forward to integrate TRAP with splunk&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 16:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/371355#M67418</guid>
      <dc:creator>ylucena</dc:creator>
      <dc:date>2019-12-03T16:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/509371#M86649</link>
      <description>&lt;P&gt;Just checking in to see if there has been any updates on proofpoint TRAP integration. I have been able to get the events into Splunk via syslog, but parsing is another matter. Unless I missed something I don't see any TA currently available in Splunkbase.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 18:35:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/509371#M86649</guid>
      <dc:creator>riegelo</dc:creator>
      <dc:date>2020-07-15T18:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/640625#M109334</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I know it passed quite a long time, but I am struggling to import TRAP logs into Splunk too.&lt;BR /&gt;Any news about this? Where did you set up syslog forwarding?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 15:12:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/640625#M109334</guid>
      <dc:creator>lpino</dc:creator>
      <dc:date>2023-04-19T15:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/640827#M109340</link>
      <description>&lt;P&gt;Hello! Any news about TRAP the integration?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 12:50:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/640827#M109340</guid>
      <dc:creator>lpanella</dc:creator>
      <dc:date>2023-04-20T12:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/671264#M112518</link>
      <description>&lt;P&gt;Hello, we have a requirement for this as well. Is there any update to this discussion? We have a need to integrate data sourced from ThreatResponse into our splunk solution.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 14:05:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/671264#M112518</guid>
      <dc:creator>jbuckner85</dc:creator>
      <dc:date>2023-12-08T14:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Resource/guide sought for ProofPoint TRAP [ThreatResponse] integration with Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/692359#M115105</link>
      <description>&lt;P&gt;Any chance that there will be a Splunk integration for TRAP?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 19:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Resource-guide-sought-for-ProofPoint-TRAP-ThreatResponse/m-p/692359#M115105</guid>
      <dc:creator>rferg06</dc:creator>
      <dc:date>2024-07-03T19:27:04Z</dc:date>
    </item>
  </channel>
</rss>

