All Apps and Add-ons

Guidance on Configuring Proofpoint - ET Splunk TA in Splunk Cloud

pramod
New Member

I am trying to configure the Proofpoint - ET Splunk TA on Splunk Cloud, and during the setup, it asks for an API key and an authorization code. While I have the API key, I noticed that the authorization code appears as "None", so I provided the Oink code instead. However, when I try to save the configuration, it does not get applied.

Is there a specific way to configure this on Splunk Cloud? Any guidance on setting up ET Intelligence correctly would be greatly appreciated.
Thank you 

 

 

Labels (1)
0 Karma

asimit
Path Finder

Hi @pramod,

 

I've worked with the Proofpoint ET Splunk TA in Splunk Cloud, and there's a specific way to handle the authentication for this app.

For configuring the Proofpoint ET Intelligence in Splunk Cloud, you need to understand that there's a difference between the "authorization code" and the "Oink code":

1. The API key is what you get from your ET Intelligence subscription.

2. The "authorization code" field in the TA configuration actually requires your ET Intelligence subscription key (sometimes also called "download key"), NOT the Oink code. This is a common confusion point.

3. If you're seeing "None" for the authorization code, it's likely because that field hasn't been properly populated in your account settings on the Proofpoint ET Intelligence portal.

Here's how to properly configure it:

1. Log in to your ET Intelligence account at https://threatintel.proofpoint.com/

2. Navigate to "Account Settings" (usually in the top-right profile menu)

3. Make sure both your API key and subscription key (download key) are available - if your subscription key shows "None", contact Proofpoint support to have it properly provisioned

4. In Splunk Cloud:
a. Install the Proofpoint ET Splunk TA through the Splunk Cloud self-service app installation
b. Open the app configuration
c. Enter your API key in the "API Key" field
d Enter your subscription key (download key) in the "Authorization Code" field (NOT the Oink code)
e. Save the configuration

5. If you're still getting errors, check the following:
a. Look at the _internal index for any API connection errors
b. Verify your Splunk Cloud instance has proper outbound connectivity to the Proofpoint ET Intelligence API endpoints
c. Confirm with Proofpoint that your subscription is active and properly configured

If you're still having issues after trying these steps, you may need to:
1. Submit a support ticket with Proofpoint to verify your account credentials
2. Work with Splunk Cloud support to ensure the app is properly installed and has the right permissions

Please give 👍 for support 😁 happly splunking .... 😎

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...