<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Integrating Proofpoint TAP into XSIAM in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/integrating-proofpoint-tap-into-xsiam/m-p/596990#M73</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like some guidance on which data source I should use when integrating Proofpoint TAP into XSIAM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the content pack "Proofpoint TAP" on the marketplace,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a data source named "Proofpoint TAP".&amp;nbsp; This data source has the ability to fetch alerts, and it ingests into the "proofpoint_tap_v2_generic_alert_raw" data set. However it does not come with an associative data modeling rule.&amp;nbsp; It does come with a correlation rule "Proofpoint TAP v2 Alerts (automatically generated)"&lt;/P&gt;
&lt;P&gt;This method appears to have come from installing the &lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/ProofpointTAP/" target="_self"&gt;Proofpoint TAP content pack&lt;/A&gt; on the marketplace&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is another data source named "Proofpoint Targeted Attack Protection" which can also fetch alerts, and it ingests into the "proofpoint_tap_raw" data set. It does come with a data modeling rule "[MODEL: dataset=proofpoint_tap_raw, content_id="ProofpointTAP"]"&amp;nbsp; but it does not come with an associative correlation rule.&lt;/P&gt;
&lt;P&gt;This method appears to be installed available by default&amp;nbsp;&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Ingest-Logs-from-Proofpoint-Targeted-Attack-Protection" target="_self"&gt;XSIAM documentation&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both of these are stated to be supported by Palo Alto XSIAM.&amp;nbsp; Why the difference here?&amp;nbsp; Which one should be used?&amp;nbsp; Should both be used, but in different ways?&amp;nbsp; Why doesn't one come with a data modeling rule and why doesn't the other come with a basic correlation rule?&amp;nbsp; Is the documentation out of date.&amp;nbsp; Should the customer be redirected in the documentation to use the one in the&amp;nbsp;"Proofpoint TAP" content pack?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2024 15:33:44 GMT</pubDate>
    <dc:creator>amcdonal363</dc:creator>
    <dc:date>2024-09-05T15:33:44Z</dc:date>
    <item>
      <title>Integrating Proofpoint TAP into XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/integrating-proofpoint-tap-into-xsiam/m-p/596990#M73</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like some guidance on which data source I should use when integrating Proofpoint TAP into XSIAM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the content pack "Proofpoint TAP" on the marketplace,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a data source named "Proofpoint TAP".&amp;nbsp; This data source has the ability to fetch alerts, and it ingests into the "proofpoint_tap_v2_generic_alert_raw" data set. However it does not come with an associative data modeling rule.&amp;nbsp; It does come with a correlation rule "Proofpoint TAP v2 Alerts (automatically generated)"&lt;/P&gt;
&lt;P&gt;This method appears to have come from installing the &lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/ProofpointTAP/" target="_self"&gt;Proofpoint TAP content pack&lt;/A&gt; on the marketplace&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is another data source named "Proofpoint Targeted Attack Protection" which can also fetch alerts, and it ingests into the "proofpoint_tap_raw" data set. It does come with a data modeling rule "[MODEL: dataset=proofpoint_tap_raw, content_id="ProofpointTAP"]"&amp;nbsp; but it does not come with an associative correlation rule.&lt;/P&gt;
&lt;P&gt;This method appears to be installed available by default&amp;nbsp;&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Administrator-Guide/Ingest-Logs-from-Proofpoint-Targeted-Attack-Protection" target="_self"&gt;XSIAM documentation&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both of these are stated to be supported by Palo Alto XSIAM.&amp;nbsp; Why the difference here?&amp;nbsp; Which one should be used?&amp;nbsp; Should both be used, but in different ways?&amp;nbsp; Why doesn't one come with a data modeling rule and why doesn't the other come with a basic correlation rule?&amp;nbsp; Is the documentation out of date.&amp;nbsp; Should the customer be redirected in the documentation to use the one in the&amp;nbsp;"Proofpoint TAP" content pack?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 15:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/integrating-proofpoint-tap-into-xsiam/m-p/596990#M73</guid>
      <dc:creator>amcdonal363</dc:creator>
      <dc:date>2024-09-05T15:33:44Z</dc:date>
    </item>
  </channel>
</rss>

