When you configure your Proofpoint Protection Server to send log data to USM Appliance, you can use the Proofpoint Protection Server plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin.
Device | Details |
---|---|
Vendor | Proofpoint |
Device Type | Unified Threat Management |
Connection Type | Syslog |
Data Source Name | Proofpoint-ps |
Data Source ID | 1875 |
Integrating Proofpoint Protection Server
Before you configure the Proofpoint Protection Server integration, you must have the IP Address of the USM ApplianceSensor.
- Log in to the Proofpoint Protection Server management console and navigate to Reports > Log Settings.
- Under Remote Log Options, add the following:
- Syslog Host: Enter the IP address of the USM Appliance Sensor.
- Syslog Port: Enter 514.
- Syslog Protocol: Specify UDP.
- Level: Set level to Information.
- Syslog MTA Enable: Select disabled.
- Save the changes.
Plugin Enablement
For plugin enablement information, see Enable Plugins.
Additional Resources and Troubleshooting
For troubleshooting, refer to the vendor documentation: