Proofpoint on Demand (PoD) Log API
The PoD Log API is Proofpoint's streaming surface rather than a request/response one: a client opens a WebSocket to logstream.proofpoint.com and subscribes to either the filter (message) log or the MTA (maillog) stream, then receives events continuously. It is the only event-shaped Proofpoint API, and it is the one whose documentation is not public — help.proofpoint.com redirects the PoD Log API article to a customer login.