The Proofpoint Essentials Modular Input add-on enables a seamless integration between Proofpoint Essentials and Splunk. It allows security operations professionals to simplify their workflow by ingesting events for the following scenarios into Splunk:
• Blocked or permitted clicks to threats recognized by Proofpoint URL Defense
• Blocked or delivered messages that contain threats recognized by Proofpoint URL Defense or Proofpoint Attachment Defense
Documentation about the structure and meaning each event produced by the can be found here: https://help.proofpoint.com/Essentials/Additional_Resources/API_Documentation/Essentials_Threat_API