Skip to main content
Warning
This app is archived. App archiving documentation
Salesforce Reports app icon

Salesforce Reports

Provides method to consume Salesforce.com reports via REST API without SOQL/SOSL queries to be indexed, put in kvstore, or both. Take your existing reports or build new ones via the Salesforce.com UI and automate their ingestion into Splunk without the fuss of developer consoles or complex salesforce query languages.Built by Evan Davison
splunk product badge

Default Version 1.0.4

July 6, 2017

Compatibility

Splunk Enterprise

Rating
5
(2)

Log in to rate this app

Support
Archived Add-on

Provides method to consume Salesforce.com reports via REST API without SOQL/SOSL queries to be indexed, put in kvstore, or both. Take your existing reports or build new ones via the Salesforce.com UI and automate their ingestion into Splunk without the fuss of developer consoles or complex salesforce query languages. This add-on provides a modular input to connect to Salesforce.com via user credentials and "security token" with options to index reports to a configurable index, store the responses to Splunk's kvstore, or both. If storing reports to the kvstore, the input includes configuration options to: - Create and update a kvstore (knowledge object) and specify its name - Create and update a lookup (knowledge object) and specify its name - Define a "key fieldname" from report to be used as the "_key" record for the kvstore (one or more comma delimited fields may be specified to define a unique record) - Purge the kvstore at each update (deletes all records in the kvstore at each update)