Splunk Delivers Real-Time Salesforce Visibility with New Streaming API Integration

You might already be using Splunk to manage your Salesforce environment with the help of the Splunk App for Salesforce and the Splunk Add-on for Salesforce that allows a Splunk administrator to collect different types of data from Salesforce using REST APIs. This solution is great and the events give you an idea of how users interact with Salesforce. These events can range from Apex executions to page views. You can access the events in the form of an event log file through the Lightning Platform REST and SOAP APIs. But these events are only made available on a daily basis or hourly basis and stored for 30 days. And what if you want these events and more at your disposal in real-time?

Great news … Splunk and Salesforce have your back.

Salesforce has created a new Streaming API that is available at no extra cost as part of Salesforce’s powerful Event Monitoring capability. Real-time events are critical to immediately identify and respond to internal and external threats to sensitive data or performance bottlenecks. For organizations with hundreds of thousands of Salesforce users, real-time data is also much easier to consume rather than waiting hours for a batch of logs to be uploaded.

But wait ... there's more! Salesforce has rearchitected events available via the Streaming API to include much richer contextual data in the event along with a variety of new events. These include machine learning-generated events that are created when Salesforce detects a session hijacking attack, credential stuffing, or anomalous user activity plus Mobile Security activity and Permission Set activity (currently in pilot).

Splunk is happy to announce we’ve expanded our integrations with Salesforce to help our users collect logs and events in real-time using the Splunk Add-on for SFDC Streaming API.

With this add-on, Splunk will leverage Salesforce's Streaming API and Real-Time Event Monitoring Objects to ingest all the above-mentioned streaming events into Splunk in real-time. Streaming API enables the streaming of events using push technology and provides a subscription mechanism for receiving events in near real-time. The subscription mechanism supports multiple types of events, including PushTopic events, generic events, platform events, and Change Data Capture events. This provides greater, real-time insights into:

Below is an example of Login events that were generated in real-time due to failed login attempts with invalid passwords. The event generates more information than events via the traditional REST endpoint with fields such as Username, location, web client details among others.

Here is another example of how you can create an alert using real-time Report events when a user exports large amounts of reports within a short period.

The add-on is simple and easy to use. To get access to all the above-mentioned good stuff, simply download and install the add-on on your Splunk environment. Then create a connection to your salesforce environment with OAuth credentials and set up data inputs for any of the streaming real-time objects. The add-on is available for use on both Splunk Enterprise and Splunk Cloud. The add-on can also be run on the same Splunk instance as the existing Salesforce app and add-on. More information on setup and troubleshooting tips are available here.

Looking to do even more with Splunk and Salesforce? Good news — this is just the tip of the iceberg of what our teams are working on together. Stay tuned for more.

And if you plan to join us at .conf21 don’t miss the opportunity to hear Salesforce share lessons learned from their internal implementation of Splunk at scale - PLA1679A - Salesforce + Splunk: A Journey of Scaling & Adoption.

Related Articles

Unlocking New Possibilities: Splunk and AWS Better Together
Partners
5 Minute Read

Unlocking New Possibilities: Splunk and AWS Better Together

Discover how Splunk and AWS are revolutionizing security and AI/ML for EMEA organizations. Learn about federated search for S3, SageMaker integration, and real-world analytics innovations from the recent Splunk Partner Team event in Amsterdam.
Executive Q&A: Accelerating AI Success with Splunk and AWS
Partners
4 Minute Read

Executive Q&A: Accelerating AI Success with Splunk and AWS

Two leaders discuss shaping the future of AI: Hao Yang, VP & Head of AI at Splunk, and Bill Fine, Product Leader – Agentic AI at AWS.
Accelerate Operations with AI: New Splunk and AWS Integrations
Partners
5 Minute Read

Accelerate Operations with AI: New Splunk and AWS Integrations

Two new integrations with AWS have created seamless workflows that activate your Splunk data where it lives, removing friction and accelerating time-to-value.
Introducing Splunk Victoria Experience on Google Cloud: Faster, Clearer, More Resilient
Partners
3 Minute Read

Introducing Splunk Victoria Experience on Google Cloud: Faster, Clearer, More Resilient

Splunk VE is now available on Google Cloud, giving organizations and admins a more transparent, responsive, and flexible Splunk Cloud Platform experience.
Splunk Cloud Platform: Accelerating Digital Resilience for the Agentic AI Era in Kingdom of Saudi Arabia with Google Cloud
Partners
2 Minute Read

Splunk Cloud Platform: Accelerating Digital Resilience for the Agentic AI Era in Kingdom of Saudi Arabia with Google Cloud

We're thrilled to announce the availability of Splunk Cloud Platform on Google Cloud in the Kingdom of Saudi Arabia.
How Splunk and Dataminr Work Together to Help Accelerate Resilience
Partners
2 Minute Read

How Splunk and Dataminr Work Together to Help Accelerate Resilience

Splunk and Dataminr deliver real-time intelligence and automated response to help organizations anticipate threats, reduce noise, and strengthen cyber resilience.
Splunk Named 2025 Americas Partner of the Year Finalist by Microsoft
Partners
2 Minute Read

Splunk Named 2025 Americas Partner of the Year Finalist by Microsoft

Splunk has been named a 2025 Microsoft Americas Partner of the Year Finalist in the Software Development Company (SDC) award category.
Managed Enterprise Platform: Delivering Mission-Critical Observability with Splunk
Partners
3 Minute Read

Managed Enterprise Platform: Delivering Mission-Critical Observability with Splunk

Learn how Accenture Federal Services partnered with Splunk to deliver a comprehensive observability solution for one of America's largest federal financial agencies.
The Partner Advantage: Splunk .conf25 Unveils the Future of AI-Native Digital Resilience
Partners
5 Minute Read

The Partner Advantage: Splunk .conf25 Unveils the Future of AI-Native Digital Resilience

Splunk .conf25 delivered a clear message to the partner ecosystem: we're entering a new era of AI-native digital resilience, and partners are at the center of this transformation.