Proofpoint Protection Server (PPS)
This pack provides a Cortex XSOAR integration for Proofpoint Protection Server.
Additionally, it supports Syslog-based log ingestion from Proofpoint Protection Server and includes parsing and modeling rules (XDM mapping) for Cortex XSIAM.
Configuration on Proofpoint Server Side
- Log in to the Proofpoint Protection Server interface.
- Click
Logs and Reports. - Click
Log Settings. - Go to the Remote Log Options panel.
- From
Syslog ProtocolSelect TCP or UDP. - In
Syslog Host, type the IP address or Hostname of your Broker VM. - In
Syslog Port, type 514 or any other preferred port. - Enable the
Syslog Filter Enableby clicking On. - In the
Facilitylist select the local1 value. - In the
Levellist select the Information value. - Enable
Syslog MTA Enableby clicking On. - In the
Facilitylist select the mail value. - In the
Levellist select the Information value. - Click the
Save Changes.
To review the Proofpoint Protection Server Syslog forwarding docs, click here.
Collect Events from Proofpoint Protection Server
In order to use the collector, use the Broker VM option.
Broker VM
To create or configure the Broker VM, use the information described here.
You can configure the specific vendor and product for this instance.
Navigate to Settings > Configuration > Data Broker > Broker VMs.
Go to the apps tab and add the Syslog app. If it already exists, click the Syslog app and then click Configure.
Click Add New.
When configuring the Syslog Collector, set the following values (not relevant for CEF and LEEF formats)
Parameter: : Value : ProtocolSet the Syslog Protocol defined on Proofpoint PS side (TCP or UDP) PortEnter the Syslog Port that Cortex XSIAM Broker VM should listen on for receiving forwarded events from Proofpoint PS VendorEnter proofpointProductEnter ps


