All Apps and Add-ons

Splunk App for Salesforce: Why am I unable to pull information from Custom Salesforce Objects?

chustwayte
Explorer

We are trying to pull information in from Custom Salesforce Objects. When trying to pull this information we are not getting anything back. I do not see any error messages in the log either. I have tried to build this information from the add data GUI form and through the inputs.conf file. I have verified that I am able to pull all the information in Salesforce workbench and I am also able to pull "standard" Salesforce tables such as accounts, products, etc. Any help would be greatly appreciated.

0 Karma
1 Solution

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

View solution in original post

0 Karma

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

0 Karma

aftasuncion
Explorer

Hello! I know this post is 3 years old now but I'm experiencing the same thing but still no luck. 

0 Karma

Wabesman
New Member

Same issue here. The default inputs work but when I try to add additional inputs or custom inputs I receive an error. 

message=[{"message":"\nUserId,Username,UserType FROM LoginEvent WHERE EventDate>2020-09-29T00:00:00.000z\n ^\nERROR at Row:1:Column:448\nsObject type 'LoginEvent' is not supported. If you are attempting to use a custom object, be sure to append the '__c' after the entity name. Please reference your WSDL or the describe call for the appropriate names
.","errorCode":"INVALID_TYPE"}]

This is even after I input the __c after the object name. I put in a ticket to Splunk support as well. Hoping to get some answers because the default logins input does not give us all logins from Salesforce users. We are also looking for changes by admins events.

Thanks, 

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...