In this article, you'll learn how to integrate Proofpoint's Email Security and Protection product with Real-Time Coaching. Once the integration is complete, data from Proofpoint will be available for use under the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in Proofpoint
Before you set up the integration in Real-Time Coaching, you'll need to obtain your Proofpoint Client ID and API key. Proofpoint uses a service principal and secret to authenticate to the SIEM API. To obtain these items, follow the steps below:
- Log in to your Proofpoint console
- Navigate to the Threat Insight Dashboard.
- Select Settings.
- Select Connected Applications. The Service credentials section will open.
- In the Name section, select Create New Credential and enter a name for your credential.
- Select Generate.
- Locate your Client ID and API Key and save them to a place that you can easily access. You'll need these items to set up the integration in Real-Time Coaching.
Set Up the Integration in Real-Time Coaching
Once you have your Proofpoint Client ID and API key, you can set up the integration in Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Proofpoint vendor tile and select Configure.
- Enter the Client ID and the API Key.
- Select Authorize.
Map Your Users
After you've finished integrating Proofpoint, you can map your users either through mapping rules (recommended) or through a CSV file upload. For more information about user mapping, see our user mapping article.
Manage Detection Rules
Once you've successfully authorized this integration, you can also manage Proofpoint detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the Proofpoint integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Proofpoint vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.