本文にスキップ

Salesforce Event Monitoring Integration

Overview

Salesforce Event Monitoring provides visibility into user activity, login history, and API usage within your Salesforce organization. KYRA MDR collects these events for security monitoring and compliance. Requires Salesforce Shield or Event Monitoring add-on.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Salesforce org with Event Monitoring or Shield license
  • Connected App with API access configured
  • System Administrator or equivalent profile

Configuration

Configure Salesforce Connected App:

  1. In Salesforce Setup, navigate to App Manager > New Connected App
  2. Enable OAuth settings:
    • Callback URL: https://login.salesforce.com/services/oauth2/callback
    • OAuth Scopes: api, event_api
  3. Note the Consumer Key and Consumer Secret
  4. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: salesforce
login_url: https://login.salesforce.com
client_id: <consumer-key>
client_secret: <consumer-secret>
username: <service-user>
password: <password+security-token>
poll_interval: 300s
  1. Restart the collector service

Collected Log Types

Log TypeDescriptionSecurity Use
LoginUser login and logout eventsBrute force, geographic anomaly detection
APIAPI call eventsAPI abuse, data extraction
Report ExportReport download eventsData exfiltration monitoring
URIPage view eventsUser activity monitoring
LightningLightning component eventsApplication usage tracking
Apex ExecutionCustom code execution eventsCode-level auditing

Troubleshooting

No event logs: Salesforce Event Monitoring requires a Shield or Event Monitoring add-on license.

Authentication errors: Ensure the connected app is approved and the service user has the API Enabled permission.

Large data volumes: Event log files can be very large. Set a longer poll interval (300-600s) to avoid API limits.

Contact kyra@seekerslab.com for support.