Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create an event profile for the Proofpoint Integration for Security Operations

Create an event profile to identify the events you want to import from the Proofpoint product.

About this task

You create an event profile by configuring event types, mappings and import schedules. A progress bar on the page displays all the steps and is highlighted for the currently active configuration.

Before you begin

Role required: sn_si_admin

Procedure

  1. Navigate to All > SIR Integration with Proofpoint > Proofpoint Events Profile.

  2. On the Events Profiles page, select New.

  3. On the form, fill in the fields.

    The progress bar is displayed starting with Name.

FieldDescription
NameName for the event profile. Consider using a name that includes the associated event type:- Clicks Blocked - Clicks Permitted - Messages Blocked - Messages Delivered
SourceThe source configured for the integration on the Integration Configurations page.
OrderThe order in which this profile is run. The default value is 100.
ActiveOption for activating the profile.
DescriptionOptional description for this event profile.
  1. Select Continue.

  2. Choose one or more event types by moving them from the Available column to the Selected column.

    The available event types are:

    • Clicks Blocked
    • Clicks Permitted
    • Messages Blocked
    • Messages Delivered
    • Select Continue.

    The configuration steps related to the selected event type or types are displayed in the progress bar.

    The values for the Source Fields are provided from the targeted attack protection (TAP) data in your environment as a reference.

    The default mapping of the source fields data to the target fields is displayed on the page. Basic data is included as a guide, but you can modify this mapping.

  3. Select the f(x) icon to view the default translations included with the application.

    Multiple values for a field are separated by commas.

  4. Select Continue.

  5. In the Filtering and Aggregations page, configure the properties in the following table.

    OptionDescription
    Filter based on conditions for Message EventsOption to enable filtering based on message events.
    Message Events Filter ConditionsMessage event filter conditions.
    Filter based on conditions for Click EventsOption to enable filtering based on click events.
    Click Events Filter ConditionsClick event filter conditions.
    Aggregation ConditionsOption to allow an incoming incident to be appended to an open security incident instead of creating a new one.
    Incident fields with matching valuesAdd the Security Incident Response fields whose values must be matched for an incident to be included in an aggregation.
    Log work note for New IncidentOption to enable work notes to be logged to the parent Security Incident Response.
    Enable ThreatID RelationOption to enable aggregation of all incidents that have matching ThreatIDs.
  6. Select Continue.

  7. Select one of the import type and how often you want to import event data.

OptionDescription
Ongoing Events IngestionOption to import events at a regular interval that is defined with a start date, an end date, and the polling interval in minutes.- Polling increment (minutes): Interval in minutes between imports - Set Initial Events Ingestion Time - Input initial Ingestion Time
One Time RetrievalOption to import events only once on the basis of the date configured. All the events from the selected date are imported.Provide a start date for the event import (Since date).
  1. Select Finish.

Result

The newly created event profile is included in the list of existing event profiles on the Events Profiles page.