Proofpoint Protection Server (PPS)
This pack provides a Cortex XSOAR integration for Proofpoint Protection Server.
Additionally, it supports Syslog-based log ingestion from Proofpoint Protection Server and includes parsing and modeling rules (XDM mapping) for Cortex XSIAM.
Configuration on Proofpoint Server Side
- Log in to the Proofpoint Protection Server interface.
- Click
Logs and Reports
. - Click
Log Settings
. - Go to the Remote Log Options panel.
- From
Syslog Protocol
Select TCP or UDP. - In
Syslog Host
, type the IP address or Hostname of your Broker VM. - In
Syslog Port
, type 514 or any other preferred port. - Enable the
Syslog Filter Enable
by clicking On. - In the
Facility
list select the local1 value. - In the
Level
list select the Information value. - Enable
Syslog MTA Enable
by clicking On. - In the
Facility
list select the mail value. - In the
Level
list select the Information value. - Click the
Save Changes
.
To review the Proofpoint Protection Server Syslog forwarding docs, click here.
Collect Events from Proofpoint Protection Server
In order to use the collector, use the Broker VM option.
Broker VM
To create or configure the Broker VM, use the information described here.
You can configure the specific vendor and product for this instance.
- Navigate to Settings > Configuration > Data Broker > Broker VMs.
- Go to the apps tab and add the Syslog app. If it already exists, click the Syslog app and then click Configure.
- Click Add New.
- When configuring the Syslog Collector, set the following values (not relevant for CEF and LEEF formats):
-----------------------------------------------------------------------------------------------------------------------------------------------------------
| Parameter: : | Value : |
|-------------------------|-------------------------------------------------------------------------------------------------------------------------------|
|Protocol
| Set the Syslog Protocol defined on Proofpoint PS side (TCP or UDP) |
|Port
| Enter the Syslog Port that Cortex XSIAM Broker VM should listen on for receiving forwarded events from Proofpoint PS |
|Vendor
| Enterproofpoint
|
|Product
| Enterps
|