Skip to main content

Did anyone integrate Proofpoint On Demand logs with SecOps SIEM?

I didn't find proper documentation for integrating PoD logs into SIEM. SecOps SIEM is asking for providing Authentication HTTP headers as below:

Authorization: Bearer <JSON web token>
Sec-WebSocket-Key: <key>

I have configured the feed and logs are not ingesting. But the feed is not in failed status. 

I was able to generate only API key from the proofpoint admin portal.

Have you seen the docs mentioned in this previous community post: Ingesting Proofpoint On Demand logs


Reply