ProofPoint - SIEM
  • 02 Apr 2025
  • 1 Minute to read
  • Dark
    Light
  • PDF

ProofPoint - SIEM

  • Dark
    Light
  • PDF

Article summary

ProofPoint - SIEM

Description

IntegrationProofPoint's SIEM Integration is an automated solution for businesses that allows them to quickly and easily integrate their security information and event management (SIEM) system with their ProofPoint security platform. This integration allows businesses to collect, analyze, and respond to security threats in real-time, providing a comprehensive view of the security landscape. The integration also enables businesses to take advantage of advanced analytics and machine learning to detect and respond to threats faster, while reducing the time and effort required to manually configure and manage security policies. With the integration, businesses can leverage the power of their SIEM system to gain deeper insights into their security posture and identify potential threats before they become a problem. Additionally, the integration provides a unified view of security events across the entire organization, allowing businesses to quickly identify and respond to threats before they become a problem. With the integration, businesses can significantly reduce their risk of data breaches and protect their valuable assets.

Trigger Request

  • HTTP Post Request

  • Headers:

KeyValue
Content-Typeapplication/json
  • Json body parameters:
ParametersTypeDescription
datestringThe approximate timestamp (date and time) of the event to investiagte. The query will be from 30mins earlier to 30mins later that this timestamp.
formatstringA string specifying the format in which data is returned (syslog - default - or JSON).
threatStatusstringA string specifying which threat statuses will be returned in the data (active, cleared or falsePositive).
threatTypestringA string specifying which threat type will be returned in the data (url, attachment or messageText)

Supported CDC Versions

  • 2.8

Was this article helpful?