Splunk Enterprise Security

Splunk Add-on For Salesforce

linaaabad
Observer

Are there pre-configured or default Dashboards associated with this Add-on?  Is the Add-on suppose to show up under App when it's installed? 

Labels (2)
0 Karma

linaaabad
Observer

Is it possible to get the Search Strings or Source code from the Splunk App for Salesforce???? Anyone have the App and can provide the source code/search.? 

We installed the Splunk Add on for Salesforce with doesn't have any dashboards, we can not install the Splunk App for Salesforce because it's not supported by Splunk...

Suggestions, Help PLEASE!

0 Karma

yeahnah
Motivator

Hi @linaaabad 

The Splunk App for Salesforce is a search head app containing views and dashboards shared by a Splunk community member as a starting point for other users, like yourself, to get a head start at looking at and understanding the SF event data.  Splunk would have no interest in providing a search head app for Salesforce as they are not experts in the Salesforce data.  Being limited to only using Splunk produced apps will only slow down any development in understanding the SF data.

Having said that, an app is just an archive file containing configuration in flat text files - *.conf file and *.xml files for dashboards/views.  You do not have to install the app to be able to view these files, simply download the app and open the archive file using your favored utility, e.g. zip on Windows or tar on *nix and look at these types of  files under the default folder.  If you are not very experienced in Splunk then it will be a confusing place to start, however.

Alternatively, if there is a test system you could install the app you could look at the configuration via the Web UI and copy what you want to your other system.

Hope that helps a little bit. 
 

0 Karma

yeahnah
Motivator

Hi @linaaabad 

This is a 3rd party Splunk app that relies on the Splunk Add-on For Salesforce so it's likely that it has some compatibility.

Splunk App for Salesforce: https://splunkbase.splunk.com/app/1931

Hope that helps

Tags (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...