Copyright (c) 2010-2019 by Proofpoint, Inc. All Rights Reserved.
Proofpoint On Demand, Proofpoint Protection Server and the Proofpoint logos are trademarks or registered trademarks of Proofpoint, Inc.
About | Proofpoint On Demand Email Security App |
Developer | Proofpoint, Inc. |
App Version | 2.1.0 |
App Build | 57 |
Technology Add-on (TA) | Proofpoint On Demand Email Security Add On |
Technology Add-on (TA) | Proofpoint TAP SIEM Modular Input |
Folder Name | pps_ondemand |
Vendor Products | Proofpoint On Demand 8.0 and above |
Target Attack Protection | |
Has index-time operations | False |
Create an index | False |
Implements summarization | False |
Splunk Enterprise versions | 9.0, 8.2, 8.1 |
CIM | 4.8+ |
Platforms | Platform Independent |
Requires Splunk Restart | Yes |
In a single server deployment, single instance of Splunk Enterprise functions as data collection node, indexer and search head. In such deployment, install the add-ons Proofpoint Email Security Add-On and Proofpoint TAP SIEM Modular Input. After that, install Proofpoint Email Security App For Splunk.
In a distributed deployment, typically a combination of forwarders are deployed for data collection, separate indexer nodes for data ingestion and search heads for data visualization are deployed. We recommend installing our Add-Ons on both Forwarder and Search heads and the App on the search head.
Component | Forwarder | Indexer | Search head |
Proofpoint On Demand Email Security Add-on | Install | No (Note) | Install |
Proofpoint TAP SIEM Modular Input 1.0.1 available (TA) | Install | No (Note) | Install |
Proofpoint On Demand Email Security App | No | No | Install |
Note: When there is no forwarder, you will have to install the Add-on on Indexer.
By default this app uses the "main" index to look for Proofpoint logs. To change this to an index that the Proofpoint On Demand Email Security Add-on uses, you need to edit the pps_get_index macro. Here are the steps:
By default, the data model acceleration is not enabled. You need to enable this to make sure the dashboards show the realtime data.
Note: Please wait few minutes after the changing the Acceleration settings to check the dashboard.
Updated the dashboards to use jquery version 3.5
Updates in 2.0.0 release
1. Support for Splunk 8 with compatibility for both Python 2 and 3.
2. Minor changes to TLS dashboard.
3. Proofpoint Icon updated according to recent branding changes.
4. CIM mapping changes
Version 1.0.0
Dec. 17, 2018
This App is designed to work with Proofpoint On Demand Email Security Add On.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.