Proofpoint
StandardProofpoint provides a unified solution against advanced email threats. Logpoint aggregates and normalizes the Proofpoint logs so you can analyze the information through dashboards. Proofpoint’s dashboard visualizes event details for the Targeted Attack Protection (TAP) click and message events. Proofpoint TAP monitors the email flow for malicious URLs and objects. Upon detecting the malicious content, the TAP service triggers an alert to Threat Response for further investigation.
Enhancements
KB-22751
Added Syslog Collector based Proofpoint log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
KB-10649
Renamed the rcpts field as receiver in ProofpointCompiledNormalizer .
KB-2066573971
ProofpointTAPCompiledNormalizer now normalizes Proofpoint Targeted Attack Protection logs with syslog header.
The log_host and process fields are now normalized by ProofpointTAPCompiledNormalizer.
KB-753934149
Added a new compiled normalizer ProofpointTAPCompiledNormalizer that supports the Proofpoint Targeted Attack Protection logs.
Past Releases
Proofpoint v5.1.2 ▾
Enhancements
KB-10649
Renamed the rcpts field as receiver in ProofpointCompiledNormalizer .
KB-2066573971
ProofpointTAPCompiledNormalizer now normalizes Proofpoint Targeted Attack Protection logs with syslog header.
The log_host and process fields are now normalized by ProofpointTAPCompiledNormalizer.
Proofpoint v5.1.0 ▾
Enhancement
KB-753934149
Added a new compiled normalizer ProofpointTAPCompiledNormalizer that supports the Proofpoint Targeted Attack Protection logs.
Proofpoint v3.1.2 ▾
Enhancement
A minor update has been done in Proofpoint's normalizer for better signature handling.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.