Salesforce Real-Time Event Monitoring
You can integrate Salesforce Real-Time Event Monitoring with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Salesforce Real-Time Event Monitoring product overview
Salesforce Real-Time Event Monitoring, part of Salesforce Shield, lets organizations monitor user activity and security events across their Salesforce org in near real time. It streams a broad set of event types, such as logins, API calls, report exports, and page interactions, through the Salesforce Streaming API, and includes Threat Detection, which uses machine learning to identify anomalous and potentially malicious activity.
What we ingest
Sophos XDR consumes logs from Salesforce Real-Time Event Monitoring through the Salesforce Streaming API, for the event types you enable for streaming. The following log categories are collected:
- Authentication events: Login, logout, and login-as activity.
- Activity events: API calls, report and list view access, Lightning and URI page access, permission set changes, and file activity.
- Threat detection events: Salesforce Threat Detection events, including credential stuffing, session hijacking, report anomaly, and guest user anomaly.
Event and data types
We ingest the following event and data types from Salesforce Real-Time Event Monitoring:
- Authentication events: User login, logout, and login-as activity, including the user, source, and result. Normalized to authentication telemetry.
- Activity events: User and system activity across API, report, list view, page (Lightning and URI), permission set, and file events, including the actor, object, and operation. Normalized to HTTP and cloud audit telemetry.
- Threat detection events: Salesforce machine-learning threat detections such as credential stuffing, session hijacking, report anomaly, and guest user anomaly, including the threat type, user, and score. Normalized to third-party security alert telemetry.
Data provided by this integration
Data provided by Salesforce Real-Time Event Monitoring gets normalized to the following schemas:
authcloudaudithttpthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.