Hello Splunkers,
We are using "Splunk Add-on for Salesforce" to pull the SalesForce event logs from SalesForce.
Logs are updated hourly and daily at the SalesForce. At Splunk Heavy Forwarder, inputs are configured with interval of 1 hour (3600 seconds). But Splunk is receiving those logs on a daily basis only even though it is configured to receive hourly.
Not sure what the problem is.
Hi mayurr98
The problem you described is a know issue and you can get a patch to fix the problem.
Contact Splunk support and get a patch for Salesforce Add on to fix data collection issue.
Hope this helps.