Configure for Arctic Wolf monitoring

You can configure to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • An active account with Organization Admin or Channel Admin privileges
  • An active domain configured in

Verify deployment

  1. Sign in to the Admin Portal.
  2. Go to Administration > Account Management > Integrations.
  3. Verify that all of these conditions are true:
    • Integration status is Connected.
    • The deployment method is correct for your organization.
    • Email traffic is actively flowing through .

Verify recommended security features in

These features are recommended because they generate additional security telemetry that Arctic Wolf can collect. Availability depends on your license.

  1. In the Admin Portal, go to Administration > Account Management > Features.
  2. Verify that these features are enabled, as applicable to your licensed subscription:
    Feature Purpose
    URL Defense Detects and protects against malicious URLs.
    Attachment Defense Detects known malicious attachments.
    Attachment Defense Sandboxing Analyzes unknown attachments in a sandbox.
    Anti-Spoofing Policies Helps detect spoofed emails.
    Email Warning Tags Adds banners to suspicious emails.

Generate credentials

  1. In the Admin Portal, go to Administration > Account Management > Integrations.
  2. Select the Integration Keys tab.
  3. Click Add Integration Key.
  4. Configure these settings:
    • Name — Enter a descriptive name. For example, enter Arctic Wolf.
    • Access Type — Select SIEM Threat Events.
  5. Click Generate.
  6. Copy the Integration Key and Integration Secret, and then save them in a safe, encrypted location.
    CAUTION: The integration secret is displayed only once. Save it before leaving the page.

Provide credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. Klicken Sie im Navigationsmenü auf Datenerfassung > Cloud-Sensoren.
  3. Click Add Account +.
  4. On the Add Account page, click Proofpoint Essentials.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • Region — Select US or EU, based on your account region.
    • API Key — Enter the Integration Key that you saved in Generate credentials.
    • API Key Secret — Enter the Integration Secret that you saved in Generate credentials.
    • Credential Expiry — Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.