Proofpoint Logs

Panther supports pulling logs directly from Proofpoint

Overview

Panther has the ability to fetch Proofpoint logs by querying the Proofpoint SIEM API.

How to onboard Proofpoint logs to Panther

To onboard Proofpoint logs, you will generate Proofpoint API credentials, then create a Proofpoint source in Panther.

Step 1: Create API credentials in Proofpoint

  1. Log in to Proofpoint.

  2. Navigate to Settings.

  3. Click New Token, and generate a token.

    • Save the Token Service Principal and Token Secret you generate in a secure location, as you will need them in the next step.

Step 2: Create a Proofpoint source in Panther

  1. In the left-side navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “Proofpoint,” then click its tile.

  4. In the slide-out panel, click Start Setup.

  5. Enter a descriptive Name for the source, e.g., "My Proofpoint logs."

  6. Click Setup.

  7. On the Set Credentials page, enter values for the following fields:

    • Proofpoint Domain: Enter the domain name of your Proofpoint instance, e.g., https://tap-api-v2.proofpoint.com.

    • Token Service Principal: Enter the value you generated in Proofpoint in Step 1.

    • Token Secret: Enter the value you generated in Proofpoint in Step 1.

  8. Click Setup. You will be directed to a success screen:\

    The success screen reads, "Everything looks good! Panther will now automatically pull & process logs from your account"
    • You can optionally enable one or more Detection Packs.

    • The Trigger an alert when no events are processed setting defaults to YES. We recommend leaving this enabled, as you will be alerted if data stops flowing from the log source after a certain period of time. The timeframe is configurable, with a default of 24 hours.\

      The "Trigger an alert when no events are processed" toggle is set to YES. The "How long should Panther wait before it sends you an alert that no events have been processed" setting is set to 1 Day

Supported log types

Proofpoint.Event

Proofpoint.Event logs represent activity within a Proofpoint instance. For more information, see Proofpoint's documentation.

Last updated

Was this helpful?