Exploring the Proofpoint Integration for Security Operations

  • 릴리스 버전: Australia
  • 업데이트 날짜 2026년 03월 12일
  • 소요 시간: 2분
  • You can configure event profiles in SIR to ingest events from Proofpoint. SIR creates an incident for each ingested event which analysts can review or work on.

    Proofpoint Integration for Security Operations users

    표 1. Users
    User Description
    Security admin

    Create event profiles for filtering the ingested events. SIR creates incidents for these the ingested events.

    Proofpoint Integration for Security Operations benefits

    표 2. Proofpoint Integration for Security Operations benefits
    Benefit Feature Users
    Pull event data into your instance and create security incidents. Review security incidents from a single location for events deemed suspicious or malicious.

    If the delivered email messages and permitted clicks are later deemed malicious, chances are these messages were opened and interacted with by your employees. To track these messages for review, automatically create security incidents based on the event profiles you create and configure for message traffic for the integration.

    Additionally, you can also enable creating security incidents for the blocked messages and clicks for audit purposes.

    Managers