Getting Data In

How do you deploy Splunk ProofPoint Add-in?

marlongarcia
New Member

Hi All -

I'm new with Splunk and currently just started learning the Fundamentals. I just received a request to setup and configure ProofPoint RSyslog in Splunk.

Hoping to give me more information and instruction how to setup the Proofpoint add-in in Splunk.

Thank you in advance and any inputs and suggestion is highly appreciated.

0 Karma

adonio
Ultra Champion

Hello and Welcome to Splunk!
start with a little reading on the ProofPOint Side:
https://www.proofpoint.com/us/technology-partners/splunk
then dive in to how the app integrates: (there are 2 add-ons and i always forget which one trumps)
https://splunkbase.splunk.com/app/3080/#/details - this one i think works with syslog
https://splunkbase.splunk.com/app/3681/ - this one is with API Modular Input
enjoy answers from other members asking the same question you do:
https://answers.splunk.com/answers/405250/how-to-pull-logs-into-splunk-from-proofpoint-via-a.html

hope it helps and enjoy the journey!

0 Karma

marlongarcia
New Member

Thank you Adonio for the links. Will definitely check this and keep you posted.

Hopefully I can successfully setup the PP in Splunk.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...