I have installed the splunk add-on for salesforce and I have completed the configuration. I have received data until 19th september for "login history" object. I am using "sfdc" index only. Then data pulling is stopped after that. But there is a data until 4th oct in that object in slaesforce site. Why the data is not reflecting in splunk?
This happened to me as well. It could be that your Splunk Integration User had "Manage Users" removed from it's permissions, which is needed to view the LoginHistory object.
Our workaround was to use the User object and LoginEvent to retrieve the same type of data.
@hariniramesh Could you please update the solution if any?