Salesforce Integration
Salesforce Event Monitoring and Shield audit ingestion for CRM security.
What this integration does
Salesforce meets agentic SOC
Salesforce Event Monitoring provides granular logs of user activity, API calls, report exports, and login events. ManySignal ingests Salesforce event logs via the EventLogFile API and Salesforce Shield Real-Time Event Monitoring, enabling detection of CRM data exfiltration, compromised user accounts, and insider threats targeting customer and revenue data.
Salesforce EventLogFile API ingestion for all event log types
Real-Time Event Monitoring via Salesforce Shield Streaming
Login anomaly and new session IP detection
Data collected
- Login event logs with session details, IP, and MFA status
- Report run and export events with record count
- API call logs for REST, SOAP, and Bulk API
- Lightning component interaction events
- Connected app OAuth grant and revocation events
Actions supported
- Terminate active Salesforce user sessions via API
- Reset user password and force re-authentication
- Revoke OAuth access token for a connected app
- Alert on report export exceeding row threshold
Getting started
Set up in minutes
- 1
Enable Event Monitoring
- 2
Create a Connected App
- 3
Configure ManySignal connector
- 4
Set data export alert thresholds
Salesforce Integration: frequently asked questions
Is Event Monitoring included in all Salesforce editions?
Event Monitoring is a paid add-on for Enterprise and Unlimited editions. Basic login history is available in all editions without Event Monitoring. Salesforce Shield provides real-time streaming events.
How frequently are EventLogFiles available?
Hourly EventLogFiles are available within 3 hours of occurrence. Daily EventLogFiles are available the following day. ManySignal ingests hourly files for near-real-time detection.
Can ManySignal detect CRM data exfiltration?
Yes. ManySignal detects mass report exports, bulk API calls extracting large record sets, and data loader usage outside approved IP ranges as data exfiltration indicators.
Does this work with Salesforce sandboxes?
Yes. Configure a separate connector for each Salesforce org (production, sandbox, scratch orgs) using distinct Connected App credentials.
What is Salesforce Shield and how does it differ?
Salesforce Shield adds Field Audit Trail (field-level history), Platform Encryption, and Real-Time Event Monitoring. ManySignal supports all three: EventLogFiles (standard Event Monitoring) and Shield Streaming events.
Can ManySignal detect when a Salesforce admin adds a new user?
Yes. User provisioning events appear in the Setup Audit Trail log type in EventLogFiles. ManySignal ingests these and alerts on unexpected admin-level user creation.
How are Lightning Community (Experience Cloud) events handled?
Salesforce Experience Cloud events appear in EventLogFiles as distinct event types. ManySignal ingests Guest User login attempts, which are a common attack surface.
Does ManySignal support Salesforce connected to external identity providers?
Yes. When Salesforce uses an external IdP (Okta, Entra ID) for SSO, ManySignal correlates Salesforce login events with the IdP authentication events for complete context.
Can I monitor Salesforce API access from third-party applications?
Yes. Connected app OAuth events and API event logs include the connected app name and API user, enabling monitoring of third-party integration activity.
What is the response time from event to ManySignal detection?
For hourly EventLogFiles: up to 3 hours. For Salesforce Shield Real-Time Event Monitoring: under 2 minutes. Shield streaming is recommended for high-priority security monitoring.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.