Salesforce Event Monitoring Integration
Overview
Salesforce Event Monitoring provides visibility into user activity, login history, and API usage within your Salesforce organization. KYRA MDR collects these events for security monitoring and compliance. Requires Salesforce Shield or Event Monitoring add-on.
Prerequisites
- A KYRA MDR Collector installed and running
- Salesforce org with Event Monitoring or Shield license
- Connected App with API access configured
- System Administrator or equivalent profile
Configuration
Configure Salesforce Connected App:
- In Salesforce Setup, navigate to App Manager > New Connected App
- Enable OAuth settings:
- Callback URL:
https://login.salesforce.com/services/oauth2/callback - OAuth Scopes:
api,event_api
- Callback URL:
- Note the Consumer Key and Consumer Secret
- Configure the KYRA MDR collector:
sources: - type: salesforce login_url: https://login.salesforce.com client_id: <consumer-key> client_secret: <consumer-secret> username: <service-user> password: <password+security-token> poll_interval: 300s- Restart the collector service
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Login | User login and logout events | Brute force, geographic anomaly detection |
| API | API call events | API abuse, data extraction |
| Report Export | Report download events | Data exfiltration monitoring |
| URI | Page view events | User activity monitoring |
| Lightning | Lightning component events | Application usage tracking |
| Apex Execution | Custom code execution events | Code-level auditing |
Troubleshooting
No event logs: Salesforce Event Monitoring requires a Shield or Event Monitoring add-on license.
Authentication errors: Ensure the connected app is approved and the service user has the API Enabled permission.
Large data volumes: Event log files can be very large. Set a longer poll interval (300-600s) to avoid API limits.
Contact kyra@seekerslab.com for support.