Same issue here. The default inputs work but when I try to add additional inputs or custom inputs I receive an error. message=[{"message":"\nUserId,Username,UserType FROM LoginEvent WHERE EventDate>2020-09-29T00:00:00.000z\n ^\nERROR at Row:1:Column:448\nsObject type 'LoginEvent' is not supported. If you are attempting to use a custom object, be sure to append the '__c' after the entity name. Please reference your WSDL or the describe call for the appropriate names .","errorCode":"INVALID_TYPE"}] This is even after I input the __c after the object name. I put in a ticket to Splunk support as well. Hoping to get some answers because the default logins input does not give us all logins from Salesforce users. We are also looking for changes by admins events. Thanks,
... View more