All Apps and Add-ons

In the Splunk SalesForce add-on, why am I getting 404 on log files?

kaydub00
Explorer

I've set up the SalesForce Add-on and all seemed to be working. The plug-in went back over 30 days and started parsing files fine. Once it got to 1/30, they started failing.

When I investigated the _internal log for errors, I saw many 404 errors when pulling the logfile from SalesForce.

I pulled the 52 URLs from the _internal log pointing at the SalesForce logfiles and tried to pull them manually. I still received a 404. I then went to the SalesForce developer workbench and used SOQL to pull a list of all of our SalesForce event log files. I then cross-referenced what I found in the _internal log and noticed that none of the files exist.

So Splunk is trying to pull files from SalesForce that doesn't exist.

Any help here? Anyone experienced this before?

All my SF objects are being ingested properly. It's just the SalesForce Event Logfiles. So I have no new events from 1/31 and onward from the event log files.

Why is Splunk trying to pull non-existent files?

martinrowe
New Member

Hi @kaydub00 , did you resolve this issue? I'm experiencing something similar. Thanks.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...