All Apps and Add-ons

Guidance on Configuring Proofpoint - ET Splunk TA in Splunk Cloud

pramod
New Member

I am trying to configure the Proofpoint - ET Splunk TA on Splunk Cloud, and during the setup, it asks for an API key and an authorization code. While I have the API key, I noticed that the authorization code appears as "None", so I provided the Oink code instead. However, when I try to save the configuration, it does not get applied.

Is there a specific way to configure this on Splunk Cloud? Any guidance on setting up ET Intelligence correctly would be greatly appreciated.
Thank you 

 

 

Labels (1)
0 Karma

asimit
Path Finder

Hi @pramod,

 

I've worked with the Proofpoint ET Splunk TA in Splunk Cloud, and there's a specific way to handle the authentication for this app.

For configuring the Proofpoint ET Intelligence in Splunk Cloud, you need to understand that there's a difference between the "authorization code" and the "Oink code":

1. The API key is what you get from your ET Intelligence subscription.

2. The "authorization code" field in the TA configuration actually requires your ET Intelligence subscription key (sometimes also called "download key"), NOT the Oink code. This is a common confusion point.

3. If you're seeing "None" for the authorization code, it's likely because that field hasn't been properly populated in your account settings on the Proofpoint ET Intelligence portal.

Here's how to properly configure it:

1. Log in to your ET Intelligence account at https://threatintel.proofpoint.com/

2. Navigate to "Account Settings" (usually in the top-right profile menu)

3. Make sure both your API key and subscription key (download key) are available - if your subscription key shows "None", contact Proofpoint support to have it properly provisioned

4. In Splunk Cloud:
a. Install the Proofpoint ET Splunk TA through the Splunk Cloud self-service app installation
b. Open the app configuration
c. Enter your API key in the "API Key" field
d Enter your subscription key (download key) in the "Authorization Code" field (NOT the Oink code)
e. Save the configuration

5. If you're still getting errors, check the following:
a. Look at the _internal index for any API connection errors
b. Verify your Splunk Cloud instance has proper outbound connectivity to the Proofpoint ET Intelligence API endpoints
c. Confirm with Proofpoint that your subscription is active and properly configured

If you're still having issues after trying these steps, you may need to:
1. Submit a support ticket with Proofpoint to verify your account credentials
2. Work with Splunk Cloud support to ensure the app is properly installed and has the right permissions

Please give 👍 for support 😁 happly splunking .... 😎

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...