<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Salesforce lookup table error in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/679290#M2869</link>
    <description>&lt;P&gt;got it thank you.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 14:57:33 GMT</pubDate>
    <dc:creator>tv00638481</dc:creator>
    <dc:date>2024-03-01T14:57:33Z</dc:date>
    <item>
      <title>Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675609#M2779</link>
      <description>&lt;P&gt;Hi ,&lt;BR /&gt;We have onboarded Salesforce in our environment. However when we run the queries, we could notice below errors are getting continuously across the instance whenever any query is being run and also showing on all the dashboards.&lt;BR /&gt;&lt;BR /&gt;[idx-i- xxxx.splunkcloud.com,idx-i-04xxxx.xxxx.splunkcloud.com,idx-i-075xxx.xxx.splunkcloud.com.idx-i-&lt;BR /&gt;Oaxxx.xxxx.splunkcloud.com,idx-i-0be.xxxx splunkcloud.com,sh-i-026xxx.xxxx.splunkcloud.com] Could not load lookup=LOOKUP-SFDC-USER_NAME&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 13:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675609#M2779</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2024-01-27T13:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675615#M2784</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262528"&gt;@tv00638481&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Make sure&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/3549" target="_self"&gt;Splunk Add-on for Salesforce&lt;/A&gt; is installed on the search head and verify the lookup_sfdc_usernames KV store lookup definition is shared globally and accessible to everyone who needs to use Salesforce App for Splunk.&lt;/P&gt;&lt;P&gt;Also make sure the Lookup - USER_ID to USER_NAME saved search is enabled and scheduled. This is the search that populates the lookup. To improve performance, modify the saved search to user your Salesforce index instead of index=*. Splunk normally uses macros to specify indexes, but that was overlooked in this add-on.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2024 22:11:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675615#M2784</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-01-27T22:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675632#M2785</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;On SH, we are not getting this error.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We getting these errors on ES and the app is available there and it's &amp;nbsp;accessible globally. We are running query specific to Salesforce index only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 06:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675632#M2785</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2024-01-28T06:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675634#M2786</link>
      <description>&lt;P&gt;If you're using Splunk Cloud Classic Experience, the add-on needs to be installed on your ES SH as well.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 06:10:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675634#M2786</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-01-28T06:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675673#M2788</link>
      <description>&lt;P&gt;Addon is also installed.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 11:29:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675673#M2788</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2024-01-28T11:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675680#M2789</link>
      <description>&lt;P&gt;What happens you run the following command from &amp;lt;your_stack_url&amp;gt;/app/splunk-app-sfdc/search:&lt;/P&gt;&lt;P&gt;| inputlookup&amp;nbsp;lookup_sfdc_usernames&lt;/P&gt;&lt;P&gt;Do you see any results?&lt;/P&gt;&lt;P&gt;Do you have any duplicate definitions of&amp;nbsp;LOOKUP-SFDC-USER_NAME under Settings &amp;gt; Lookups &amp;gt; Automatic Lookups with App: All and Owner: Any?&lt;/P&gt;&lt;P&gt;When you search against sourcetype=sfdc:loginhistory, do you still see errors? You can view search logs from Job &amp;gt; Inspect Job. In search.log, search for&amp;nbsp;LOOKUP-SFDC-USER_NAME to see additional context. To view logs from indexers, add noop to your search:&lt;/P&gt;&lt;P&gt;index=your_index sourcetype=sfdc:loginhistory&lt;BR /&gt;| noop remote_log_fetch=*&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 17:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675680#M2789</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2024-01-28T17:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675988#M2796</link>
      <description>&lt;P&gt;The reason you are getting this message is because the indexers do not have the&amp;nbsp;&lt;SPAN&gt;LOOKUP-SFDC-USER_NAME&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The following &lt;A href="https://splunk.my.site.com/customer/s/article/Error-Could-not-load-lookup-Name-of-Lookup-Error-Could-not-load-lookup-Name-of-Lookup" target="_self"&gt;Knowledge Article&lt;/A&gt; explains what is happening.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To get off this message I would suggest you open a support case and the Splunk Cloud engineer will be able to address this for you.&lt;/P&gt;&lt;P&gt;Robertino&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 02:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/675988#M2796</guid>
      <dc:creator>rbudini_splunk</dc:creator>
      <dc:date>2024-01-31T02:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/676089#M2801</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I could get the results when I run the command. My observation about the lookup file &amp;nbsp;between SH and ES on SH is , the .CSV extension is missing.once added it's running.&lt;/P&gt;&lt;P&gt;I'm trying understand the below query to implement.&lt;/P&gt;&lt;P&gt;Firstly, the description provided in &amp;nbsp; the usecase is not clearly understood . I got this usecase from the splunk SF content search.&lt;/P&gt;&lt;P&gt;Anyone has idea about this query.&lt;/P&gt;&lt;P&gt;&lt;A href="https://lantern.splunk.com/Splunk_Platform/UCE/Security/Threat_Hunting/Protecting_a_Salesforce_cloud_deployment/Spike_in_exported_records_from_Salesforce_cloud" target="_blank" rel="noopener"&gt;https://lantern.splunk.com/Splunk_Platform/UCE/Security/Threat_Hunting/Protecting_a_Salesforce_cloud_deployment/Spike_in_exported_records_from_Salesforce_cloud&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;ROWS_PROCESSED&amp;gt;0 EVENT_TYPE=API OR EVENT_TYPE=BulkAPI OR EVENT_TYPE=RestAPI
|lookup lookup_sfdc_usernames USER_ID
|bucket _time span=1d 
|stats sum(ROWS_PROCESSED) AS rows BY _time Username
|stats count AS num_data_samples max(eval(if(_time &amp;gt;= relative_time(maxtime, "-1d@d"), 'rows',null))) AS rows avg(eval(if(_time&amp;lt;relative_time(maxtime,"-1d@d"),'rows',null))) AS avg stdev(eval(if(_time&amp;lt;relative_time(maxtime,"-1d@d"),'rows',null))) AS stdev BY Username
|eval lowerBound=(avg-stdev*2), upperBound=(avg+stdev*2)
|where 'rows' &amp;gt; upperBound AND num_data_samples &amp;gt;=7&lt;/PRE&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 15:25:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/676089#M2801</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2024-01-31T15:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Salesforce lookup table error</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/679290#M2869</link>
      <description>&lt;P&gt;got it thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 14:57:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Salesforce-lookup-table-error/m-p/679290#M2869</guid>
      <dc:creator>tv00638481</dc:creator>
      <dc:date>2024-03-01T14:57:33Z</dc:date>
    </item>
  </channel>
</rss>

