All Apps and Add-ons

Splunk App for Salesforce: Why am I unable to pull information from Custom Salesforce Objects?

chustwayte
Explorer

We are trying to pull information in from Custom Salesforce Objects. When trying to pull this information we are not getting anything back. I do not see any error messages in the log either. I have tried to build this information from the add data GUI form and through the inputs.conf file. I have verified that I am able to pull all the information in Salesforce workbench and I am also able to pull "standard" Salesforce tables such as accounts, products, etc. Any help would be greatly appreciated.

0 Karma
1 Solution

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

View solution in original post

0 Karma

chustwayte
Explorer

I was able to figure this out. It appears that the problem I was running into for it was trying to do to many new queries to quickly. I have found that adding a new data source and giving it about an hour to populate (or longer depending on the number of results expected back) before adding another data source that everything works correctly. I have indexed about 1/2 a dozen different queries now and each time it indexes correctly. I have also found that if the start date and order by fields are not filled out with valid information that results my be in completely. Hopefully this helps other people in the future!

0 Karma

aftasuncion
Explorer

Hello! I know this post is 3 years old now but I'm experiencing the same thing but still no luck. 

0 Karma

Wabesman
New Member

Same issue here. The default inputs work but when I try to add additional inputs or custom inputs I receive an error. 

message=[{"message":"\nUserId,Username,UserType FROM LoginEvent WHERE EventDate>2020-09-29T00:00:00.000z\n ^\nERROR at Row:1:Column:448\nsObject type 'LoginEvent' is not supported. If you are attempting to use a custom object, be sure to append the '__c' after the entity name. Please reference your WSDL or the describe call for the appropriate names
.","errorCode":"INVALID_TYPE"}]

This is even after I input the __c after the object name. I put in a ticket to Splunk support as well. Hoping to get some answers because the default logins input does not give us all logins from Salesforce users. We are also looking for changes by admins events.

Thanks, 

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...