All Apps and Add-ons

Official/robust Splunk/Salesforce integration

dantonag
Explorer

Hello,
Salesforce is becoming the global leader in CRM/Sales services, but Splunk doesn't seem to have a "certified" or "official" solution to index Salesforce events/log data/etc.

The only app for Salesforce/Splunk integration is "TA-SFDC", that is highly unsupported and unreliable (we've tested it).

Is Splunk planning for a solution to index cloud (Salesforce in particular) data?

Thanks in advance.

Tags (3)

johnchris
Engager

Yes we have just build such a tool doing it across multiple cloud apps and send to any SIEM or Splunk.

Have a look at
https://splunkbase.splunk.com/app/2932/

This is our module called 'SkyFormation Extend' that is doing exactly this for any business cloud app as Salesforce, Google App, ServiceNow, Office 365 and more. We extarct the events unified and classify them then send to Splunk ready for action.
It is a Java app you can install as on-premise on any machine you want, and it will take you 5 minutes to set it up.

John C

jcampaz
New Member

Hi. You can try to use the Splunk Cloud App. It has SFDC integration. I am currently testing it now. Looks pretty good so far.

0 Karma

greg21102
New Member

There are just a few "official" or "certified" Splunk apps. Most are made by the community / 3rd parties. Why not join the development community by making a Salesforce app?

0 Karma

dantonag
Explorer

We've already heavily modified the TA-SFDC app for our needs and fixed some bugs, but we don't have time and resources to build a full-fledged app. Splunk should build an integration with cloud systems more closely into the product IMHO.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...