Linking Proofpoint TAP as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Proofpoint TAP (Targeted Attack Protection) connector syncs your email security data – blocked and permitted clicks, blocked and delivered messages – into PostHog, so you can analyze email threat activity, track attack patterns, and correlate security findings with the rest of your data.
Prerequisites
You need a Proofpoint TAP subscription and a service principal with a secret. In the TAP dashboard, go to Settings > Connected Applications, create a new service principal, and save the generated credentials.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
When linking Proofpoint TAP, you'll need:
- Service principal – the service principal ID from Connected Applications.
- Secret – the secret key associated with your service principal.
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All tables (clicks_blocked, clicks_permitted, messages_blocked, messages_delivered) support incremental and full refresh syncs. Incremental syncs use the query_end_time cursor field and merge records by their unique IDs.
The Proofpoint TAP API retains only seven days of event history, so the first sync (and any full refresh) reaches back almost seven days with a two-minute buffer at the retention boundary. We recommend syncing at least once daily to avoid losing data.
Proofpoint TAP rate-limits API access to 1,800 requests per rolling day for the clicks_permitted endpoint, with 1,800 requests shared across the other three endpoints.
Configuration
| Option | Type | Required |
|---|---|---|
Service principal | text | Yes |
Secret | password | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
clicks_blocked | Blocked clicks on malicious URLs. | Incremental, Full refresh | query_end_time | — |
clicks_permitted | Permitted clicks on malicious URLs. | Incremental, Full refresh | query_end_time | — |
messages_blocked | Quarantined messages with detected threats. | Incremental, Full refresh | query_end_time | — |
messages_delivered | Delivered messages with detected threats. | Incremental, Full refresh | query_end_time | — |
| Table | Primary key | Event time field | Description |
|---|---|---|---|
clicks_blocked | id | clickTime | Blocked URL clicks from email messages |
clicks_permitted | id | clickTime | Permitted URL clicks from email messages |
messages_blocked | GUID | messageTime | Blocked email messages |
messages_delivered | GUID | messageTime | Delivered email messages |
Troubleshooting
If you see 401 errors, your service principal or secret is incorrect. Double-check your credentials in the TAP dashboard under Settings > Connected Applications.
If you see 403 errors, your credentials don't have permission to access this customer's data. Verify access permissions in the TAP dashboard.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.