Skip to main content

CollectorsCloud Collectors Administration Guide

Configure the Proofpoint On-Demand Cloud Collector

Set up the Proofpoint On-Demand Cloud Collector to continuously ingest security events from Proofpoint Endpoints Message, and Maillog.

  1. Before you configure the Proofpoint On-Demand Cloud Collector, ensure that you complete the prerequisites.

  2. Log in to the Exabeam Security Operations Platform with your registered credentials as an administrator.

  3. Navigate to Collectors > Cloud Collectors.

  4. Click New Collector.

    Proofpoint-On_demand_1.png
  5. Click Proofpoint On-Demand.

  6. Enter the following information for the cloud collector:

    Proofpoint-On_demand_2.png
    • NAME – Specify a name for the Cloud Collector instance.

    • CLUSTER ID – Enter the value for the cluster ID that you obtained while completing the prerequisites.

    • ACCESS TOKEN – Enter the value for the access that you obtained while completing the prerequisites.

    • DATA SOURCES – Select the data sources Message, or Maillog, or both from which you want the cloud collector to fetch data.

  7. (Optional) SITE – Select an existing site or to create a new site with a unique ID, click manage your sites. Adding a site name helps you to ensure efficient management of environments with overlapping IP addresses.

    By entering a site name, you associate the logs with a specific independent site. A sitename metadata field is automatically added to all the events that are going to be ingested via this collector. For more information about Site Management, see Define a Unique Site Name.

  8. (Optional) TIMEZONE – Select a time zone applicable to you for accurate detections and event monitoring.

    By entering a time zone, you override the default log time zone. A timezone metadata field is automatically added to all events ingested through this collector.

    Timezone_sitename_site_management_1.png
  9. To confirm that the Exabeam Security Operations Platform communicates with the service, click Test Connection

  10. Click Install.

    AWS_S3_2.png

    A confirmation message informs you that the new Cloud Collector is created.

    Note

    To edit the cloud collector configuration, ensure that you stop the collector instance first.