Splunk Search

Help with join query for Salesforce

linaaabad
Observer

Hello Smarties...

Can someone offer some assistance; We recently started ingesting Salesforce into Splunk, Username are coming in as ID's (00000149345543qba), instead of Jane Doe. So was told to use the Join to get the Usernames or Names, and add to the sourcetype I need "joined" with;  So I am trying to get the "Login As"  events which is under the sourcetype="sfdc:setupaudittrail" - how do I get the Login As events with usernames, if usernames are under the user index and the login as events are under the setupaudittrail sourcetype? Here is my attempted search which doesn't come up with anything; But I know the events exist...

 

index=salesforce sourcetype="sfdc:user" 
| join type=outer UserAccountId [search index=salesforce sourcetype="sfdc:setupaudittrail" Action=suOrgAdminLogin]

Labels (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi there,

without sample events this can be tricky but since you provided the SPL and you join on UserAccountId I assume this field is available in both sourcetypes.

If this is case, it would be as simple as

 

index=salesforce UserAccountId=* sourcetype="sfdc:user" OR ( sourcetype="sfdc:setupaudittrail" Action=suOrgAdminLogin )
| fields list of fields you want
| stats values(*) AS * by _time UserAccountId

 

Hope this helps ...

cheers, MuS

 

sainag_splunk
Splunk Employee
Splunk Employee

Hello @linaaabad!

@MuS solution should give you a good start. Please don't use "join" instead use stats .. by as  above.

Refer the below for documentation.
https://lantern.splunk.com/Splunk_Platform/Product_Tips/Searching_and_Reporting/Writing_better_queri...

https://conf.splunk.com/watch/conf-online.html?search=PLA1528B#/

 

 

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...