<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Salesforce EventLogFile error in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-there-Salesforce-EventLogFile-error/m-p/610973#M1742</link>
    <description>&lt;P&gt;It worked for me. The only downside is that the UI for inputs editing is broken&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2022 15:48:42 GMT</pubDate>
    <dc:creator>lianwan</dc:creator>
    <dc:date>2022-08-26T15:48:42Z</dc:date>
    <item>
      <title>Why is there Salesforce EventLogFile error?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-there-Salesforce-EventLogFile-error/m-p/562662#M1047</link>
      <description>&lt;P&gt;We can connect successfully with Salesforce TA and grab data from common objects, like Audit Trail.&lt;/P&gt;
&lt;P&gt;However, EventLogFile type can't log anything and throw those errors.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="t"&gt;2021-08-09&lt;/SPAN&gt; &lt;SPAN class="t"&gt;20:23:01&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class="t"&gt;824&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class="t"&gt;0000&lt;/SPAN&gt; &lt;SPAN class="t"&gt;log_level=ERROR&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;pid=24066&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;tid=MainThread&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;file=engine_v2.py&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;func_name=start&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;code_line_no=57&lt;/SPAN&gt;&lt;SPAN&gt; | [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;stanza_name=QA_&lt;SPAN class="t a"&gt;EVENTLOG&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;CloudConnectEngine&lt;/SPAN&gt; &lt;SPAN class="t"&gt;encountered&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exception&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Traceback&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;most&lt;/SPAN&gt; &lt;SPAN class="t"&gt;recent&lt;/SPAN&gt; &lt;SPAN class="t"&gt;call&lt;/SPAN&gt; &lt;SPAN class="t"&gt;last&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_salesforce/lib/cloudconnectlib/core/engine_v2.py&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;52&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;start&lt;/SPAN&gt; &lt;SPAN class="t"&gt;for&lt;/SPAN&gt; &lt;SPAN class="t"&gt;temp&lt;/SPAN&gt; &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;result:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_salesforce/lib/cloudconnectlib/core/job.py&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;88&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;run&lt;/SPAN&gt; &lt;SPAN class="t"&gt;contexts&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;list&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;self._running_task.perform&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;self._context&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;or&lt;/SPAN&gt;&lt;SPAN&gt; ()) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;File&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_salesforce/lib/cloudconnectlib/core/task.py&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;289&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;perform&lt;/SPAN&gt; &lt;SPAN class="t"&gt;raise&lt;/SPAN&gt; &lt;SPAN class="t"&gt;CCESplitError&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cloudconnectlib.core.exceptions.CCESplitError&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;2021-08-09 20:23:01&lt;SPAN&gt;,&lt;/SPAN&gt;822&lt;SPAN&gt; +&lt;/SPAN&gt;0000 log_level=ERROR&lt;SPAN&gt;, &lt;/SPAN&gt;pid=24066&lt;SPAN&gt;, &lt;/SPAN&gt;tid=MainThread&lt;SPAN&gt;, &lt;/SPAN&gt;file=task.py&lt;SPAN&gt;, &lt;/SPAN&gt;func_name=_send_request&lt;SPAN&gt;, &lt;/SPAN&gt;code_line_no=505&lt;SPAN&gt; | [&lt;/SPAN&gt;stanza_name=QA_&lt;SPAN class="t a"&gt;EVENTLOG&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;The response status=400 for request which url=MYCOMPANY&lt;SPAN&gt;--&lt;/SPAN&gt;qa.my.salesforce.com/services/data/v51.0/query&lt;SPAN&gt;?&lt;/SPAN&gt;q=SELECT&lt;SPAN&gt;%20&lt;/SPAN&gt;Id&lt;SPAN&gt;%2C&lt;/SPAN&gt;EventType&lt;SPAN&gt;%2C&lt;/SPAN&gt;LogDate&lt;SPAN&gt;%20&lt;/SPAN&gt;FROM&lt;SPAN&gt;%20&lt;/SPAN&gt;EventLogFile&lt;SPAN&gt;%20&lt;/SPAN&gt;WHERE&lt;SPAN&gt;%20&lt;/SPAN&gt;LogDate%3E&lt;SPAN&gt;%3D&lt;/SPAN&gt;2020-01-01T00&lt;SPAN&gt;%3A&lt;/SPAN&gt;00&lt;SPAN&gt;%3A&lt;/SPAN&gt;00.000z&lt;SPAN&gt;%20&lt;/SPAN&gt;AND&lt;SPAN&gt;%20&lt;/SPAN&gt;Interval&lt;SPAN&gt;%3D&lt;/SPAN&gt;%27Daily%27&lt;SPAN&gt;%20&lt;/SPAN&gt;ORDER&lt;SPAN&gt;%20&lt;/SPAN&gt;BY&lt;SPAN&gt;%20&lt;/SPAN&gt;LogDate&lt;SPAN&gt;%20&lt;/SPAN&gt;LIMIT&lt;SPAN&gt;%20&lt;/SPAN&gt;1000 and method=GET and message=&lt;SPAN&gt;[{"&lt;/SPAN&gt;message&lt;SPAN&gt;"&lt;/SPAN&gt;:&lt;SPAN&gt;"&lt;/SPAN&gt;\nLogDate&lt;SPAN&gt;&amp;gt;&lt;/SPAN&gt;=2020-01-01T00:00:00.000z AND Interval=&lt;SPAN&gt;'&lt;/SPAN&gt;Daily&lt;SPAN&gt;' &lt;/SPAN&gt;ORDER BY LogDate\n ^\nERROR at Row:1:Column:91\nNo such column&lt;SPAN&gt; '&lt;/SPAN&gt;Interval&lt;SPAN&gt;' &lt;/SPAN&gt;on entity&lt;SPAN&gt; '&lt;/SPAN&gt;EventLogFile&lt;SPAN&gt;'&lt;/SPAN&gt;. If you are attempting to use a custom field&lt;SPAN&gt;, &lt;/SPAN&gt;be sure to append the&lt;SPAN&gt; '&lt;/SPAN&gt;__c&lt;SPAN&gt;' &lt;/SPAN&gt;after the custom field name. Please reference your WSDL or the describe call for the appropriate names.&lt;SPAN&gt;","&lt;/SPAN&gt;errorCode&lt;SPAN&gt;"&lt;/SPAN&gt;:&lt;SPAN&gt;"&lt;/SPAN&gt;INVALID_FIELD&lt;SPAN&gt;"}]&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;We just checked and all permissions are corrected (View Event Log Files / View All Data e API Enabled).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 17:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-there-Salesforce-EventLogFile-error/m-p/562662#M1047</guid>
      <dc:creator>pedromvieira</dc:creator>
      <dc:date>2022-08-26T17:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce EventLogFile error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-there-Salesforce-EventLogFile-error/m-p/562666#M1048</link>
      <description>&lt;P&gt;If I comment the monitor interval inside inputs.conf, it works.&lt;/P&gt;&lt;P&gt;In the Splunk UI is a required field.&lt;/P&gt;&lt;P&gt;sudo cat /opt/splunk/etc/apps/Splunk_TA_salesforce/local/inputs.conf&lt;/P&gt;&lt;P&gt;[sfdc_event_log://QA_EVENTLOG]&lt;BR /&gt;account = QA&lt;BR /&gt;index = mycompany_salesforce_eventlog&lt;BR /&gt;interval = 30&lt;BR /&gt;#monitoring_interval = Daily&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_date = 2020-01-01T00:00:00.000z&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 20:47:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-there-Salesforce-EventLogFile-error/m-p/562666#M1048</guid>
      <dc:creator>pedromvieira</dc:creator>
      <dc:date>2021-08-09T20:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce EventLogFile error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-there-Salesforce-EventLogFile-error/m-p/610973#M1742</link>
      <description>&lt;P&gt;It worked for me. The only downside is that the UI for inputs editing is broken&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 15:48:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Why-is-there-Salesforce-EventLogFile-error/m-p/610973#M1742</guid>
      <dc:creator>lianwan</dc:creator>
      <dc:date>2022-08-26T15:48:42Z</dc:date>
    </item>
  </channel>
</rss>

