Skip to main content

Need help in Ingesting Proofpoint On Demand logs

  • May 14, 2025
  • 1 reply
  • 42 views

rav1and3
Forum|alt.badge.img+4

Did anyone integrate Proofpoint On Demand logs with SecOps SIEM?

I didn't find proper documentation for integrating PoD logs into SIEM. SecOps SIEM is asking for providing Authentication HTTP headers as below:

Authorization: Bearer <JSON web token>
Sec-WebSocket-Key: <key>

I have configured the feed and logs are not ingesting. But the feed is not in failed status. 

I was able to generate only API key from the proofpoint admin portal.

1 reply

kentphelps
Staff
Forum|alt.badge.img+12
  • Staff
  • May 15, 2025

Have you seen the docs mentioned in this previous community post: Ingesting Proofpoint On Demand logs