Announcing RUNWAY: The conference for teams securing what's nextRegister Now
RunReveal
SourcesSource TypesSalesforce

Salesforce Event Logs

Capture detailed information about user activities, system operations, and performance metrics within a Salesforce organization.

Salesforce Event Logs — Create External Client App

Setup

Salesforce Event Logs supports API polling to collect event logs from your Salesforce organization using OAuth 2.0 client credentials. The setup steps are the same as for Salesforce Audit Trail; you can use the same Connected App credentials for both Event Logs and Audit Trail if you want to run both sources.

API and polling: We use Salesforce API v65.0. Backfill is limited to 30 days. RunReveal checks Salesforce about every minute. The Polling Interval setting is which EventLogFile cadence we query (Daily or Hourly), not how often we call the API. New sources default to Daily.

Salesforce generates those files on a delay (this is Salesforce, not RunReveal):

Hourly logs require an add-on: Hourly EventLogFiles require the Salesforce Event Monitoring add-on with hourly logging enabled. Most orgs only have Daily logs available by default. If you do not have this add-on, set the Polling Interval to Daily in the source configuration.

Step 1: Create the External Client App

  1. In Salesforce, go to Setup (click the gear icon)
  2. In the Quick Find box, search for "External Client App Manager" (or go to AppsExternal Client AppsExternal Client App Manager in the sidebar)
  3. Click "New External Client App" in the top right
  4. Fill in the basic information:
    • Connected App Name: Your integration name (e.g. "RunReveal")
    • API Name: (auto-fills based on the name)
    • Contact Email: Your email

Salesforce Setup sidebar — path to External Client App Manager

External Client App Manager — New External Client App button

Step 2: Configure OAuth Settings

  1. Check "Enable OAuth Settings"
  2. Set Callback URL to: https://login.salesforce.com/services/oauth2/callback (or your specific callback URL if different)
  3. Under Selected OAuth Scopes, add:
    • Perform requests at any time (refresh_token, offline_access)
    • Manage user data via APIs (api)
  4. Check "Enable Client Credentials Flow"
  5. Click "Create"

OAuth Settings — Enable OAuth, Callback URL, scopes, and Client Credentials Flow

Step 3: Enable Client Credentials Flow

  1. Edit the app you just created
  2. Check "Enable Client Credentials Flow"
  3. In the "Run As" field, search for and select the execution user

The Run As user must have "API Enabled", "View Event Log Files", and "View All Data" permissions.

View Event Log Files is what grants access to the EventLogFile object. The Event Monitoring Analytics permission sets and licenses only grant the prebuilt CRM Analytics app — they do not grant access to the object itself. Without View Event Log Files, Salesforce hides EventLogFile from that user entirely rather than returning a permission error, and log collection stops.

Client Credentials Flow — Run As (Username) set to integration user

Step 4: Save and Retrieve Credentials

  1. Click "Save"
  2. Click "Continue" on the confirmation page
  3. You'll see the Consumer Key displayed immediately
  4. Click "Manage Consumer Details" to view the Consumer Secret
  5. Salesforce will send a verification code to your email — enter it to proceed
  6. Copy both the Consumer Key and Consumer Secret for use in RunReveal

External Client App Settings — Consumer Key and Secret under OAuth Settings

Step 5: Connect in RunReveal

  1. Go to Sources in RunReveal
  2. Click the Salesforce Event Logs source tile
  3. Give it a name and fill in the required fields:
    • Salesforce Instance Host: Your Salesforce instance URL (e.g. company.my.salesforce.com)
    • Client ID: The Consumer Key from Step 4
    • Client Secret: The Consumer Secret from Step 4
  4. Click Connect Source

RunReveal will start polling within a minute and backfill the last 30 days on first sync. When new EventLogFiles show up still depends on Salesforce's generation delay (hours for Hourly, at least a day for Daily).

Video Walkthrough

Verify It's Working

The source starts polling within a minute. Event log files may not exist yet — see the delay above.

You can validate we are receiving your logs by running the following SQL query.

SELECT * FROM runreveal.logs WHERE sourceType = 'salesforce' LIMIT 1

Troubleshooting

Missing event logs (or collection stopped)

If logs never appear, stop after working, or you see an error about Salesforce tables the user cannot see, the usual cause is the Run As user on the External Client App. Salesforce hides objects a user cannot read instead of returning a clear permission error. We did not need to change anything on our side for collection to stop — a profile, permission-set, or Run As user change on the Salesforce side is enough.

Confirm that user's profile (or permission sets) still includes:

PermissionNeeded for
API EnabledBoth Event Logs and Audit Trail
View Event Log FilesEvent Logs (EventLogFile)
View All DataEvent Logs
View Setup and ConfigurationAudit Trail (SetupAuditTrail) — required if the same app also feeds that source

Assigning the Event Monitoring Analytics license or permission set is not enough. Those grant the prebuilt CRM Analytics app, not EventLogFile.

If collection worked previously, check in this order:

  1. The External Client App's Client Credentials Flow → Run As user was reassigned.
  2. That user's profile, permission sets, or user license changed (including losing View Event Log Files or View All Data).

If one External Client App feeds both this source and Salesforce AuditTrail, its Run As user needs the permissions for both. Changing the Run As user or its profile to suit one source will silently stop the other, because a Client Credentials Flow has exactly one Run As user.

Event logs appear hours or a day late

That is Salesforce generating EventLogFiles, not a RunReveal outage. Hourly files typically take 3–6 hours. Daily files are unavailable for at least 1 day. See the polling callout above. If your org does not have the hourly Event Monitoring add-on, keep Polling Interval on Daily.

sObject type 'EventLogFile' is not supported

Salesforce returns this INVALID_TYPE error when the Run As user cannot read the EventLogFile object. The wording is misleading — the object has existed since API version 32.0 and has not been removed. A missing permission and a nonexistent object produce the same error.

Grant View Event Log Files, View All Data, and API Enabled, as described above and in Step 3.

Schema

The following columns are exposed for this source. RunReveal applies schema normalization across all sources, ensuring uniform field names and data types for cross-source queries and reusable detection logic.

Table: salesforce_logs (36 columns)

ColumnType
workspaceIDString
sourceIDString
sourceTypeLowCardinality(String)
sourceTTLUInt32
receivedAtDateTime
idString
eventTimeDateTime
eventNameString
eventIDString
srcIPString
srcASCountryCodeString
srcASNumberUInt32
srcASOrganizationString
srcCityString
srcConnectionTypeString
srcISPString
srcLatitudeFloat64
srcLongitudeFloat64
ColumnType
srcUserTypeString
dstIPString
dstASCountryCodeString
dstASNumberUInt32
dstASOrganizationString
dstCityString
dstConnectionTypeString
dstISPString
dstLatitudeFloat64
dstLongitudeFloat64
dstUserTypeString
actorMap(String, String)
tagsMap(String, String)
resourcesArray(String)
serviceNameString
enrichmentsArray(Tuple(data Map(String, String), name String, provider String, type String, value String))
readOnlyBool
rawLogString

Table: salesforce_login_logs (70 columns)

ColumnType
workspaceIDString
sourceIDString
sourceTypeLowCardinality(String)
sourceTTLUInt32
receivedAtDateTime
idString
eventTimeDateTime
eventNameString
eventIDString
srcIPString
srcASCountryCodeString
srcASNumberUInt32
srcASOrganizationString
srcCityString
srcConnectionTypeString
srcISPString
srcLatitudeFloat64
srcLongitudeFloat64
srcUserTypeString
dstIPString
dstASCountryCodeString
dstASNumberUInt32
dstASOrganizationString
dstCityString
dstConnectionTypeString
dstISPString
dstLatitudeFloat64
dstLongitudeFloat64
dstUserTypeString
actorMap(String, String)
tagsMap(String, String)
resourcesArray(String)
serviceNameString
enrichmentsArray(Tuple(data Map(String, String), name String, provider String, type String, value String))
readOnlyBool
ColumnType
rawLogString
eventTypeString
timestampString
requestIdString
organizationIdString
userIdString
runTimeString
cpuTimeString
uriString
sessionKeyString
loginKeyString
userTypeString
requestStatusString
dbTotalTimeString
loginTypeString
browserTypeString
apiTypeString
apiVersionString
userNameString
tlsProtocolString
cipherSuiteString
useApiTokenString
httpRefererString
loginUrlString
countryCodeString
authenticationMethodReferenceString
loginSubTypeString
authenticationServiceIdString
timestampDerivedString
userIdDerivedString
clientIpString
uriIdDerivedString
loginStatusString
sourceIpString
forwardedForIpString

Table: salesforce_logout_logs (54 columns)

ColumnType
workspaceIDString
sourceIDString
sourceTypeLowCardinality(String)
sourceTTLUInt32
receivedAtDateTime
idString
eventTimeDateTime
eventNameString
eventIDString
srcIPString
srcASCountryCodeString
srcASNumberUInt32
srcASOrganizationString
srcCityString
srcConnectionTypeString
srcISPString
srcLatitudeFloat64
srcLongitudeFloat64
srcUserTypeString
dstIPString
dstASCountryCodeString
dstASNumberUInt32
dstASOrganizationString
dstCityString
dstConnectionTypeString
dstISPString
dstLatitudeFloat64
ColumnType
dstLongitudeFloat64
dstUserTypeString
actorMap(String, String)
tagsMap(String, String)
resourcesArray(String)
serviceNameString
enrichmentsArray(Tuple(data Map(String, String), name String, provider String, type String, value String))
readOnlyBool
rawLogString
eventTypeString
timestampString
requestIdString
organizationIdString
userIdString
runTimeString
cpuTimeString
sessionKeyString
userTypeString
requestStatusString
dbTotalTimeString
browserTypeString
userNameString
timestampDerivedString
userIdDerivedString
clientIpString
sessionLevelString
sessionTypeString

Table: salesforce_apitotalusage_logs (55 columns)

ColumnType
workspaceIDString
sourceIDString
sourceTypeString
sourceTTLUInt32
receivedAtDateTime
idString
eventTimeDateTime
eventNameString
eventIDString
srcIPString
srcASCountryCodeString
srcASNumberUInt32
srcASOrganizationString
srcCityString
srcConnectionTypeString
srcISPString
srcLatitudeFloat64
srcLongitudeFloat64
srcUserTypeString
dstIPString
dstASCountryCodeString
dstASNumberUInt32
dstASOrganizationString
dstCityString
dstConnectionTypeString
dstISPString
dstLatitudeFloat64
dstLongitudeFloat64
ColumnType
dstUserTypeString
actorMap(String, String)
tagsMap(String, String)
resourcesArray(String)
serviceNameString
enrichmentsArray(Tuple(data Map(String, String), name String, provider String, type String, value String))
readOnlyBool
rawLogString
eventTypeString
timestampString
timestampDerivedString
requestIdString
organizationIdString
userIdString
userNameString
clientIpString
clientNameString
connectedAppIdString
connectedAppNameString
apiClientCategoryString
apiFamilyString
apiResourceString
apiVersionString
countsAgainstApiLimitString
entityNameString
httpMethodString
statusCodeString