Document toolboxDocument toolbox

tap.proofpoint

Introduction

The tags beginning with tap.proofpoint identify events generated by TAP products belonging to Proofpoint.

Valid tags and data tables 

The full tag must have 4 levels. The first two are fixed as tap.proofpoint. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Proofpoint TAP Isolation

tap.proofpoint.isolation.browser

tap.proofpoint.isolation.browser

tap.proofpoint.isolation.browser_and_email

tap.proofpoint.isolation.browser_and_email

tap.proofpoint.isolation.url

tap.proofpoint.isolation.url

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables:

tap.proofpoint.isolation.browser

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

hostname

str

 

 

 

user_id

str

 

 

 

username

str

 

 

 

url

str

 

 

 

date

timestamp

 

 

 

region

str

 

 

 

zone

str

 

 

 

classification

str

 

 

 

disposition

str

 

 

 

categories

str

join(categories_array, ',')

categories_array

 

at_devo_pulling_id

str

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

 

✓

tap.proofpoint.isolation.browser_and_email

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

hostname

str

 

 

 

user_id

str

 

 

 

username

str

 

 

 

url

str

 

 

 

date

timestamp

 

 

 

region

str

 

 

 

zone

str

 

 

 

disposition

str

 

 

 

categories

str

join(categories_array, ',')

categories_array

 

at_devo_pulling_id

str

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

 

✓

tap.proofpoint.isolation.url

Field

Type

Field transformation

Source field name

Extra fields

Field

Type

Field transformation

Source field name

Extra fields

eventdate

timestamp

 

 

 

hostname

str

 

 

 

user_id

str

 

 

 

username

str

 

 

 

url

str

 

 

 

date

timestamp

 

 

 

region

str

 

 

 

zone

str

 

 

 

classification

str

 

 

 

disposition

str

 

 

 

categories

str

join(categories_array, ',')

categories_array

 

at_devo_pulling_id

str

 

 

 

hostchain

str

 

 

✓

tag

str

 

 

✓

rawMessage

str

 

 

✓