All Apps and Add-ons

Guidance on Configuring Proofpoint - ET Splunk TA in Splunk Cloud

pramod
New Member

I am trying to configure the Proofpoint - ET Splunk TA on Splunk Cloud, and during the setup, it asks for an API key and an authorization code. While I have the API key, I noticed that the authorization code appears as "None", so I provided the Oink code instead. However, when I try to save the configuration, it does not get applied.

Is there a specific way to configure this on Splunk Cloud? Any guidance on setting up ET Intelligence correctly would be greatly appreciated.
Thank you 

 

 

Labels (1)
0 Karma

asimit
Path Finder

Hi @pramod,

 

I've worked with the Proofpoint ET Splunk TA in Splunk Cloud, and there's a specific way to handle the authentication for this app.

For configuring the Proofpoint ET Intelligence in Splunk Cloud, you need to understand that there's a difference between the "authorization code" and the "Oink code":

1. The API key is what you get from your ET Intelligence subscription.

2. The "authorization code" field in the TA configuration actually requires your ET Intelligence subscription key (sometimes also called "download key"), NOT the Oink code. This is a common confusion point.

3. If you're seeing "None" for the authorization code, it's likely because that field hasn't been properly populated in your account settings on the Proofpoint ET Intelligence portal.

Here's how to properly configure it:

1. Log in to your ET Intelligence account at https://threatintel.proofpoint.com/

2. Navigate to "Account Settings" (usually in the top-right profile menu)

3. Make sure both your API key and subscription key (download key) are available - if your subscription key shows "None", contact Proofpoint support to have it properly provisioned

4. In Splunk Cloud:
a. Install the Proofpoint ET Splunk TA through the Splunk Cloud self-service app installation
b. Open the app configuration
c. Enter your API key in the "API Key" field
d Enter your subscription key (download key) in the "Authorization Code" field (NOT the Oink code)
e. Save the configuration

5. If you're still getting errors, check the following:
a. Look at the _internal index for any API connection errors
b. Verify your Splunk Cloud instance has proper outbound connectivity to the Proofpoint ET Intelligence API endpoints
c. Confirm with Proofpoint that your subscription is active and properly configured

If you're still having issues after trying these steps, you may need to:
1. Submit a support ticket with Proofpoint to verify your account credentials
2. Work with Splunk Cloud support to ensure the app is properly installed and has the right permissions

Please give 👍 for support 😁 happly splunking .... 😎

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...