<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Salesforce Security Use case in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/668984#M2628</link>
    <description>&lt;P&gt;Thank you, sir, for the inputs share. Will come back if something needed.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Nov 2023 10:36:27 GMT</pubDate>
    <dc:creator>tv00638481</dc:creator>
    <dc:date>2023-11-17T10:36:27Z</dc:date>
    <item>
      <title>Salesforce Security Use case</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/668961#M2626</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm looking Security Use case on Salesforce application. Request to suggest if any please.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;BT&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 07:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/668961#M2626</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2023-11-17T07:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce Security Use case</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/668978#M2627</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262528"&gt;@tv00638481&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check these things...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Salesforce#:~:text=Salesforce%20data%20can%20be%20used,and%20for%20data%20loss%20prevention" target="_blank"&gt;https://lantern.splunk.com/Data_Descriptors/Salesforce#:~:text=Salesforce%20data%20can%20be%20used,and%20for%20data%20loss%20prevention&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is from Splunk Employee&amp;nbsp; gschatz ....For an example of a SBF use case, see how the Otto group reduces system complexity with Splunk Business Flow.&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.splunk.com/en_us/customers/success-stories/sbf-otto-group.html" rel="nofollow noopener noreferrer" target="_blank"&gt;https://www.splunk.com/en_us/customers/success-stories/sbf-otto-group.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/Anyone-Using-Splunk-App-for-Salesforce-Use-Cases/m-p/476521" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/Anyone-Using-Splunk-App-for-Salesforce-Use-Cases/m-p/476521&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk App for Salesforce - will be helpful for data onboarding and dashboards.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/1931/?_gl=1*1xlbpi3*_ga*MTUwNDQ5Mzc3NS4xNjg2Nzg4NDMw*_ga_GS7YF8S63Y*MTcwMDIxNDk3MC4zNi4xLjE3MDAyMTUzNDkuOS4wLjA.*_ga_5EPM2P39FV*MTcwMDIxNDk3MC4zOTMuMS4xNzAwMjE1MzQ5LjAuMC4w&amp;amp;_ga=2.150685874.580758828.1699758032-1504493775.1686788430" target="_blank"&gt;https://splunkbase.splunk.com/app/1931/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/partners/monitor-salesforce-s-real-time-events-with-splunk.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/partners/monitor-salesforce-s-real-time-events-with-splunk.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://lantern.splunk.com/Splunk_Platform/UCE/Security/Threat_Hunting/Protecting_a_Salesforce_cloud_deployment" target="_blank"&gt;https://lantern.splunk.com/Splunk_Platform/UCE/Security/Threat_Hunting/Protecting_a_Salesforce_cloud_deployment&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 10:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/668978#M2627</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-11-17T10:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce Security Use case</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/668984#M2628</link>
      <description>&lt;P&gt;Thank you, sir, for the inputs share. Will come back if something needed.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 10:36:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/668984#M2628</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2023-11-17T10:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce Security Use case</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/676726#M2814</link>
      <description>&lt;P&gt;I'm trying understand the below query to implement. what would be the expected result .&lt;/P&gt;&lt;P&gt;Any idea about this query.&lt;/P&gt;&lt;P&gt;&lt;A href="https://lantern.splunk.com/Splunk_Platform/UCE/Security/Threat_Hunting/Protecting_a_Salesforce_cloud_deployment/Spike_in_exported_records_from_Salesforce_cloud" target="_blank" rel="noopener nofollow noreferrer"&gt;https://lantern.splunk.com/Splunk_Platform/UCE/Security/Threat_Hunting/Protecting_a_Salesforce_cloud...&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;ROWS_PROCESSED&amp;gt;0 EVENT_TYPE=API OR EVENT_TYPE=BulkAPI OR EVENT_TYPE=RestAPI
|lookup lookup_sfdc_usernames USER_ID
|bucket _time span=1d 
|stats sum(ROWS_PROCESSED) AS rows BY _time Username
|stats count AS num_data_samples max(eval(if(_time &amp;gt;= relative_time(maxtime, "-1d@d"), 'rows',null))) AS rows avg(eval(if(_time&amp;lt;relative_time(maxtime,"-1d@d"),'rows',null))) AS avg stdev(eval(if(_time&amp;lt;relative_time(maxtime,"-1d@d"),'rows',null))) AS stdev BY Username
|eval lowerBound=(avg-stdev*2), upperBound=(avg+stdev*2)
|where 'rows' &amp;gt; upperBound AND num_data_samples &amp;gt;=7&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 11:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/676726#M2814</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2024-02-06T11:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce Security Use case</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/677022#M2824</link>
      <description>&lt;P&gt;on that same link, they have given a good search explanation. may i know if you read it.. may i know what confusion you have after reading that, thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 23:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-Security-Use-case/m-p/677022#M2824</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-02-08T23:22:42Z</dc:date>
    </item>
  </channel>
</rss>

