Configure Proofpoint Essentials for Arctic Wolf monitoring

You can configure Proofpoint Essentials® to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • An active Proofpoint Essentials account with Organization Admin or Channel Admin privileges
  • An active domain configured in Proofpoint Essentials

Verify Proofpoint Essentials deployment

  1. Sign in to the Proofpoint Essentials Admin Portal.
  2. Go to Administration > Account Management > Integrations.
  3. Verify that all of these conditions are true:
    • Integration status is Connected.
    • The deployment method is correct for your organization.
    • Email traffic is actively flowing through Proofpoint Essentials.

Verify recommended security features in Proofpoint Essentials

These features are recommended because they generate additional security telemetry that Arctic Wolf can collect. Availability depends on your Proofpoint Essentials license.

  1. In the Proofpoint Essentials Admin Portal, go to Administration > Account Management > Features.
  2. Verify that these features are enabled, as applicable to your licensed subscription:
    Feature Purpose
    URL Defense Detects and protects against malicious URLs.
    Attachment Defense Detects known malicious attachments.
    Attachment Defense Sandboxing Analyzes unknown attachments in a sandbox.
    Anti-Spoofing Policies Helps detect spoofed emails.
    Email Warning Tags Adds banners to suspicious emails.

Generate Proofpoint Essentials credentials

  1. In the Proofpoint Essentials Admin Portal, go to Administration > Account Management > Integrations.
  2. Select the Integration Keys tab.
  3. Click Add Integration Key.
  4. Configure these settings:
    • Name — Enter a descriptive name. For example, enter Arctic Wolf.
    • Access Type — Select SIEM Threat Events.
  5. Click Generate.
  6. Copy the Integration Key and Integration Secret, and then save them in a safe, encrypted location.
    CAUTION: The integration secret is displayed only once. Save it before leaving the page.

Provide Proofpoint Essentials credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Proofpoint Essentials.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • Region — Select US or EU, based on your Proofpoint Essentials account region.
    • API Key — Enter the Integration Key that you saved in Generate Proofpoint Essentials credentials.
    • API Key Secret — Enter the Integration Secret that you saved in Generate Proofpoint Essentials credentials.
    • Credential Expiry — Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.