All Apps and Add-ons

In the Splunk SalesForce add-on, why am I getting 404 on log files?

kaydub00
Explorer

I've set up the SalesForce Add-on and all seemed to be working. The plug-in went back over 30 days and started parsing files fine. Once it got to 1/30, they started failing.

When I investigated the _internal log for errors, I saw many 404 errors when pulling the logfile from SalesForce.

I pulled the 52 URLs from the _internal log pointing at the SalesForce logfiles and tried to pull them manually. I still received a 404. I then went to the SalesForce developer workbench and used SOQL to pull a list of all of our SalesForce event log files. I then cross-referenced what I found in the _internal log and noticed that none of the files exist.

So Splunk is trying to pull files from SalesForce that doesn't exist.

Any help here? Anyone experienced this before?

All my SF objects are being ingested properly. It's just the SalesForce Event Logfiles. So I have no new events from 1/31 and onward from the event log files.

Why is Splunk trying to pull non-existent files?

martinrowe
New Member

Hi @kaydub00 , did you resolve this issue? I'm experiencing something similar. Thanks.

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...