Security events
Overview
Get events for all delivered messages to blocked URLs through the Proofpoint TAP API using the HTTP Pull Listener.
HTTP Pull Listener configuration
In Falcon Onum, go to the Listeners area and click New Listener > HTTP Pull. Give a name to your new Listener and enter the following data:
Parameters
N/A
Secrets
You must define these credentials in Onum:
pp_spwill reference your Proofpoint TAP Service Principal.pp_secretwill reference your Proofpoint TAP API Secret Key.
To do it, click Add element and enter a Name for the secret (in this case, pp_sp). Then, click the Value field and select New secret to create a new one:
Give the secret a Name.
Turn off the Expiration date option.
Click Add new value and paste the secret corresponding to the value.
Click Save.
You can now select the secret you just created in the corresponding field. Repeat the process for pp_secret.
Learn more about secrets in Onum in this article.
Setup
After entering the required parameters and secrets, you can choose to manually enter the rest of configuration fields, or simply paste the given YAML:
Toggle ON the Config as YAML option to enable a free text field where you can paste the following YAML:
Temporal Window
Toggle ON to add a temporal window for events. This repeatedly shifts the time window over which data is collected.
Duration* -
5mOffset* -
5mFormat -
UTC
Authentication
Toggle ON and enter the following:
Authentication
Type* -
Basic
Basic Authentication
Username* -
${secrets.pp_sp}Password* -
${secrets.pp_secret}
Collection Phase
Pagination Type* -
NoneRequest
Response Type* -
JSONMethod* -
GETURL* -
https://tap-api-v2.proofpoint.com/v2/siem/messages/deliveredHeaders
Name -
AcceptValue -
text/plain
Query Params
Name -
formatValue -
jsonName -
intervalValue -
${temporalWindow.from}/${temporalWindow.to}
Output
Select* -
.messagesDeliveredFilter -
.Map -
.Output Mode* -
.
When you're done, click Create labels to move on to the next step and define the required Labels if needed.
Last updated
Was this helpful?

