Skip to content

Salesforce Real-Time Event Monitoring

You can integrate Salesforce Real-Time Event Monitoring with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Salesforce Real-Time Event Monitoring product overview

Salesforce Real-Time Event Monitoring, part of Salesforce Shield, lets organizations monitor user activity and security events across their Salesforce org in near real time. It streams a broad set of event types, such as logins, API calls, report exports, and page interactions, through the Salesforce Streaming API, and includes Threat Detection, which uses machine learning to identify anomalous and potentially malicious activity.

What we ingest

Sophos XDR consumes logs from Salesforce Real-Time Event Monitoring through the Salesforce Streaming API, for the event types you enable for streaming. The following log categories are collected:

  • Authentication events: Login, logout, and login-as activity.
  • Activity events: API calls, report and list view access, Lightning and URI page access, permission set changes, and file activity.
  • Threat detection events: Salesforce Threat Detection events, including credential stuffing, session hijacking, report anomaly, and guest user anomaly.

Event and data types

We ingest the following event and data types from Salesforce Real-Time Event Monitoring:

  • Authentication events: User login, logout, and login-as activity, including the user, source, and result. Normalized to authentication telemetry.
  • Activity events: User and system activity across API, report, list view, page (Lightning and URI), permission set, and file events, including the actor, object, and operation. Normalized to HTTP and cloud audit telemetry.
  • Threat detection events: Salesforce machine-learning threat detections such as credential stuffing, session hijacking, report anomaly, and guest user anomaly, including the threat type, user, and score. Normalized to third-party security alert telemetry.

Data provided by this integration

Data provided by Salesforce Real-Time Event Monitoring gets normalized to the following schemas:

  • auth
  • cloudaudit
  • http
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation