Splunk Enterprise Security

Splunk Add-on For Salesforce

linaaabad
New Member

Are there pre-configured or default Dashboards associated with this Add-on?  Is the Add-on suppose to show up under App when it's installed? 

Labels (2)
0 Karma

linaaabad
New Member

Is it possible to get the Search Strings or Source code from the Splunk App for Salesforce???? Anyone have the App and can provide the source code/search.? 

We installed the Splunk Add on for Salesforce with doesn't have any dashboards, we can not install the Splunk App for Salesforce because it's not supported by Splunk...

Suggestions, Help PLEASE!

0 Karma

yeahnah
Motivator

Hi @linaaabad 

The Splunk App for Salesforce is a search head app containing views and dashboards shared by a Splunk community member as a starting point for other users, like yourself, to get a head start at looking at and understanding the SF event data.  Splunk would have no interest in providing a search head app for Salesforce as they are not experts in the Salesforce data.  Being limited to only using Splunk produced apps will only slow down any development in understanding the SF data.

Having said that, an app is just an archive file containing configuration in flat text files - *.conf file and *.xml files for dashboards/views.  You do not have to install the app to be able to view these files, simply download the app and open the archive file using your favored utility, e.g. zip on Windows or tar on *nix and look at these types of  files under the default folder.  If you are not very experienced in Splunk then it will be a confusing place to start, however.

Alternatively, if there is a test system you could install the app you could look at the configuration via the Web UI and copy what you want to your other system.

Hope that helps a little bit. 
 

0 Karma

yeahnah
Motivator

Hi @linaaabad 

This is a 3rd party Splunk app that relies on the Splunk Add-on For Salesforce so it's likely that it has some compatibility.

Splunk App for Salesforce: https://splunkbase.splunk.com/app/1931

Hope that helps

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...