Have you followed the guidance given in the Collect Salesforce Logs documentation?
Have you followed the guidance given in the Collect Salesforce Logs documentation?
Yes, we're aware of that documentation, but we're making a direct API call, and not using an S3 bucket. There isn't an issue with the parser, we're not receiving the raw log events for SetupAuditTrail. The other event types are ingested and parsed OK.
Our Google customer engineer has confirmed SetupAuditTrail event records are arriving with a 'null' status, which suggests an issue with the Salesforce server, but we also have a Splunk SIEM making the exact same API calls with no issues.
Have you followed the guidance given in the Collect Salesforce Logs documentation?
Yes, we're aware of that documentation, but we're making a direct API call, and not using an S3 bucket. There isn't an issue with the parser, we're not receiving the raw log events for SetupAuditTrail. The other event types are ingested and parsed OK.
Our Google customer engineer has confirmed SetupAuditTrail event records are arriving with a 'null' status, which suggests an issue with the Salesforce server, but we also have a Splunk SIEM making the exact same API calls with no issues.
@BGREEN900913 did you get an answer to this?