Hi @konstr - To rule out any sort of issue with communication and verify that the problem is with the configuration of the client, would you mind running the following command from the Splunk command line? curl "https://tap-api-v2.proofpoint.com/v2/siem/all?format=json&sinceSeconds=3600" --user "principal:secret" -s - change principal:secrt to the appropriate values. If that's working, it tells us the credentials and the communication is proper. If this is successful, I suggest opening a ticket with Proofpoint support for additional assistance. We can share the final solution here for the community.
... View more