↳ GitHub sourceConnector

Proofpoint TAP (via Codeless Connector Platform)

Description

The [Proofpoint Targeted Attack Protection (TAP)](https://www.proofpoint.com/us/products/advanced-threat-protection/targeted-attack-protection) connector provides the capability to ingest Proofpoint TAP logs and events into Microsoft Sentinel. The connector provides visibility into Message and Click events in Microsoft Sentinel to view dashboards, create custom alerts, and to improve monitoring and investigation capabilities.
Declared status
1
Declared author / publisher
Proofpoint

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions on the workspace are required.
Workspace
Workspace
Proofpoint TAP API Key
A Proofpoint TAP API service principal and secret is required to access Proofpoint's SIEM API. [See the documentation to learn more about Proofpoint SIEM API](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API).

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

**Configuration steps for the Proofpoint TAP API** 1. Log into the [Proofpoint TAP dashboard](https://threatinsight.proofpoint.com/) 2. Navigate to **Settings** and go to **Connected Applications** tab 3. Click on **Create New Credential** 4. Provide a name and click **Generate** 5. Copy **Service Principal** and **Secret** values
>**NOTE:** This connector depends on a parser based on Kusto Function to work as expected [**ProofpointTAPEvent**](https://aka.ms/sentinel-ProofpointTAPDataConnector-parser) which is deployed with the Microsoft Sentinel Solution.
Service Principal
Secret

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
ProofpointTAPv2
Additional source files 2Solutions/ProofPointTap/Data Connectors/ProofpointTAP_CCP/ProofpointTAP_defination.jsonsource ↗Solutions/ProofPointTap/Data/Solution_ProofTap.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.