All Apps and Add-ons

In the Splunk SalesForce add-on, why am I getting 404 on log files?

kaydub00
Explorer

I've set up the SalesForce Add-on and all seemed to be working. The plug-in went back over 30 days and started parsing files fine. Once it got to 1/30, they started failing.

When I investigated the _internal log for errors, I saw many 404 errors when pulling the logfile from SalesForce.

I pulled the 52 URLs from the _internal log pointing at the SalesForce logfiles and tried to pull them manually. I still received a 404. I then went to the SalesForce developer workbench and used SOQL to pull a list of all of our SalesForce event log files. I then cross-referenced what I found in the _internal log and noticed that none of the files exist.

So Splunk is trying to pull files from SalesForce that doesn't exist.

Any help here? Anyone experienced this before?

All my SF objects are being ingested properly. It's just the SalesForce Event Logfiles. So I have no new events from 1/31 and onward from the event log files.

Why is Splunk trying to pull non-existent files?

martinrowe
New Member

Hi @kaydub00 , did you resolve this issue? I'm experiencing something similar. Thanks.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...