TRAP Cloud has an API to export information, but there is no Add-On to integrate TRAP Cloud with Splunk
Has anyone made this integration succesfully?
Is there intention to implement a supported Add-On on Splunk to integrate TRAP Cloud?
@kiran_panchavat we are facing similar issue, any chance you can share the py script you received from PP?
As far as I know, you can send the TRAPS using HEC token or via Syslog. Kindly check the below add-on. This Add-on is intended to be installed on Splunk Search Heads or HF's and where Splunk HEC is configured for Proofpoint TRAP.
As of now, there is no official Splunk Add-On specifically designed for integrating Proofpoint Threat Response Auto-Pull (TRAP) Cloud with Splunk. However, the "CCX Extensions for Proofpoint Products" app on Splunkbase includes a component named proofpoint:trap:hec, which is intended for integrating Proofpoint TRAP with Splunk.
https://splunkbase.splunk.com/app/6339
We investigated this add-on, but altough it mentions TRAP, there is no information provided to configure it.
TRAP Cloud integration method, as far as I know, is by API.
@solg It looks like there is nothing publicly available. We had to reach out to Proofpoint for the py script to get TRAP data in. It sounds like a question for ProofPoint.
You can download the APP and related TA's here:
App:
https://splunkbase.splunk.com/app/3727/#/details
Gateway TA:
https://splunkbase.splunk.com/app/3080/
TAP TA:
https://splunkbase.splunk.com/app/3681/