All Apps and Add-ons

Splunk App for Salesforce: Why am I unable to pull information from Custom Salesforce Objects?

chustwayte
Explorer

We are trying to pull information in from Custom Salesforce Objects. When trying to pull this information we are not getting anything back. I do not see any error messages in the log either. I have tried to build this information from the add data GUI form and through the inputs.conf file. I have verified that I am able to pull all the information in Salesforce workbench and I am also able to pull "standard" Salesforce tables such as accounts, products, etc. Any help would be greatly appreciated.

0 Karma
1 Solution

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

View solution in original post

0 Karma

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

0 Karma

aftasuncion
Explorer

Hello! I know this post is 3 years old now but I'm experiencing the same thing but still no luck. 

0 Karma

Wabesman
New Member

Same issue here. The default inputs work but when I try to add additional inputs or custom inputs I receive an error. 

message=[{"message":"\nUserId,Username,UserType FROM LoginEvent WHERE EventDate>2020-09-29T00:00:00.000z\n ^\nERROR at Row:1:Column:448\nsObject type 'LoginEvent' is not supported. If you are attempting to use a custom object, be sure to append the '__c' after the entity name. Please reference your WSDL or the describe call for the appropriate names
.","errorCode":"INVALID_TYPE"}]

This is even after I input the __c after the object name. I put in a ticket to Splunk support as well. Hoping to get some answers because the default logins input does not give us all logins from Salesforce users. We are also looking for changes by admins events.

Thanks, 

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...