This article helps you to connect your Proofpoint via SIEM to the Expel Workbench. The procedure is to port in logs by creating a new Syslog source, configuring that source in Workbench, then configure your Proofpoint via SIEM device in Workbench.
Step 1: Logging Proofpoint to a desired SIEM
Refer to your SIEM documentation or work with your SIEM representative to port in Proofpoint logs. You can also refer to the following web references for creating a new Syslog source:
Step 2: Configure the SIEM in Workbench
This link opens the Expel Help Center section for connecting SIEM-based technology to Workbench. Follow the applicable article to configure your SIEM-based tech and confirm that Proofpoint logs are flowing through and available.
Step 3: Configure Proofpoint via SIEM in Workbench
Now that you have the correct access configured and noted the credentials, you can integrate your tech with Workbench.
-
In a new browser tab, go to https://workbench.expel.io/settings/security-devices?setupIntegration=observeit_siem.
-
Complete the device fields as follows:
-
SIEM - select the SIEM that was onboarded in Step 2.
-
Name - enter the host name of the Proofpoint device.
-
Location - type the geographic location of the device.
-
-
Complete the Connection Settings fields based on the Sumo Logic SIEM you selected:
-
Source category - type the Sumo Logic source category for this device.
-
Sumologic query indices - if you are subject to Sumo Logic’s Flex pricing, you will need to provide a comma-separated list of indexes you wish Expel to query in this field. If you are on the traditional Sumo Logic pricing model, do not use this field.
If you are not sure if this applies to you or you need more information, see Considerations for Sumo Logic Flex Pricing Customers.
-