All Apps and Add-ons

Splunk App for Salesforce: Why am I unable to pull information from Custom Salesforce Objects?

chustwayte
Explorer

We are trying to pull information in from Custom Salesforce Objects. When trying to pull this information we are not getting anything back. I do not see any error messages in the log either. I have tried to build this information from the add data GUI form and through the inputs.conf file. I have verified that I am able to pull all the information in Salesforce workbench and I am also able to pull "standard" Salesforce tables such as accounts, products, etc. Any help would be greatly appreciated.

0 Karma
1 Solution

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

View solution in original post

0 Karma

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

0 Karma

aftasuncion
Explorer

Hello! I know this post is 3 years old now but I'm experiencing the same thing but still no luck. 

0 Karma

Wabesman
New Member

Same issue here. The default inputs work but when I try to add additional inputs or custom inputs I receive an error. 

message=[{"message":"\nUserId,Username,UserType FROM LoginEvent WHERE EventDate>2020-09-29T00:00:00.000z\n ^\nERROR at Row:1:Column:448\nsObject type 'LoginEvent' is not supported. If you are attempting to use a custom object, be sure to append the '__c' after the entity name. Please reference your WSDL or the describe call for the appropriate names
.","errorCode":"INVALID_TYPE"}]

This is even after I input the __c after the object name. I put in a ticket to Splunk support as well. Hoping to get some answers because the default logins input does not give us all logins from Salesforce users. We are also looking for changes by admins events.

Thanks, 

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...