↳ GitHub sourceConnector
Proofpoint TAP (via Codeless Connector Platform)
Description
The [Proofpoint Targeted Attack Protection (TAP)](https://www.proofpoint.com/us/products/advanced-threat-protection/targeted-attack-protection) connector provides the capability to ingest Proofpoint TAP logs and events into Microsoft Sentinel. The connector provides visibility into Message and Click events in Microsoft Sentinel to view dashboards, create custom alerts, and to improve monitoring and investigation capabilities.
- Declared status
- 1
- Declared author / publisher
- Proofpoint
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions on the workspace are required.
Workspace
Workspace
Proofpoint TAP API Key
A Proofpoint TAP API service principal and secret is required to access Proofpoint's SIEM API. [See the documentation to learn more about Proofpoint SIEM API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API).
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
**Configuration steps for the Proofpoint TAP API**
1. Log into the [Proofpoint TAP dashboard](https://threatinsight.proofpoint.com/)
2. Navigate to **Settings** and go to **Connected Applications** tab
3. Click on **Create New Credential**
4. Provide a name and click **Generate**
5. Copy **Service Principal** and **Secret** values
>**NOTE:** This connector depends on a parser based on Kusto Function to work as expected [**ProofpointTAPEvent**](https://aka.ms/sentinel-ProofpointTAPDataConnector-parser) which is deployed with the Microsoft Sentinel Solution.
Service Principal
Secret
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
ProofpointTAPv2
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC