Salesforce Event Collector Deprecated

Deprecated. Use Cortex XSIAM/XDR Salesforce integration instead.

Analytics & SIEM · Salesforce

Details

IDSalesforce Event Collector
ProviderSalesforce
CategoryAnalytics & SIEM
From Version6.8.0
Docker Imagedemisto/py3-tools:1.0.0.94051
Supported ModulesAgentix XSIAM EDR Cortex Cloud Cloud Runtime Security

README

Deprecated. Use XSIAM/XDR Salesforce integration instead.

Configure Salesforce Event Collector in Cortex

Parameter Description Required
Server URL   True
Client ID   True
Client Secret   True
Username   True
Password   True
Query to get Hourly Event Log Files For more information, visit the Query Hourly Event Log Files documentation https://developer.salesforce.com/docs/atlas.en-us.234.0.api_rest.meta/api_rest/event_log_file_hourly_query.htm True
How many log files to fetch   True
First fetch time interval   False
Use system proxy settings   False
Trust any certificate (not secure)   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

salesforce-get-events


Manual command to fetch events.

Base Command

salesforce-get-events

Input

Argument Name Description Required
files_limit The maximum number of log files to fetch. Default is 1. Optional
should_push_events Set this argument to True in order to create events, otherwise the command will only display them. Possible values are: True, False. Default is False. Required

Context Output

There is no context output for this command.

Configuration parameters

  • url — Server URL (required)
  • client_id — (required)
  • client_secret — (required)
  • credentials — Username (required)
  • query — Query to get Hourly Event Log Files (required)
  • files_limit — How many log files to fetch (required)
  • after — First fetch time interval
  • proxy — Use system proxy settings
  • verify — Trust any certificate (not secure)

Commands (1)

  • salesforce-get-events

    Manual command to fetch events.