⚙️ Configure Salesforce Audit Monitoring
GermainUX collects Salesforce audit information to help teams identify administrative and configuration changes that may affect security, performance, reliability, or user experience.
🔎 Audit Monitoring helps answer:
|
Question |
|---|
|
What changed in Salesforce? |
|
Who made the change? |
|
When did it occur? |
|
Which Salesforce environment was affected? |
|
Did the change coincide with a new error or performance regression? |
|
Did it affect user access, workflows, integrations, or application behavior? |
Audit Monitoring is performed by the GermainUX Engine and is enabled automatically when Salesforce monitoring is deployed through the Salesforce Application wizard.
📦 What Audit Monitoring Provides
Depending on the audit information available through Salesforce and the permissions granted to the integration user, GermainUX can monitor changes related to:
|
Area |
|---|
|
Salesforce configuration |
|
Users, profiles, permission sets, and access |
|
Connected Apps and authentication settings |
|
Objects and fields |
|
Workflows, flows, and automation |
|
Apex classes and triggers |
|
Lightning and Visualforce configuration |
|
Reports and dashboards |
|
Sharing and security settings |
|
API and integration configuration |
|
Other administrative changes recorded by Salesforce |
Each audit record may include available attributes such as:
|
Attribute |
|---|
|
Change timestamp |
|
User or administrator |
|
Action |
|
Configuration area |
|
Description |
|
Salesforce organization |
|
Environment |
|
Related object or component |
✅ Prerequisites
Before configuring Audit Monitoring, confirm that:
-
A GermainUX Engine is deployed and running.
-
Salesforce monitoring has been deployed through the Salesforce Application wizard.
-
The Salesforce OAuth connection is active.
-
The integration user can access the required Salesforce audit information.
-
The selected GermainUX Engine can reach Salesforce APIs.
-
The Salesforce organization has sufficient API capacity for the selected collection frequency.
For the initial integration, see Deploy GermainUX for Salesforce.
🚀 Enable Audit Monitoring
Audit Monitoring is enabled automatically during the initial Salesforce Application wizard deployment.
To deploy it:
-
Open GermainUX Workspace.
-
Open the left navigation menu.
-
Select Wizards.
-
Select Salesforce Application.
-
Choose the GermainUX Engine that will monitor Salesforce.
-
Enter the Salesforce connection and authentication settings.
-
Expand Show Advanced if you want to customize the audit collection interval.
-
Set Audit Monitoring Interval.
-
Complete the wizard.
The wizard creates a component with this type:
Salesforce Audit Monitor
📅 Default Collection Frequency
By default, Salesforce Audit Monitoring runs every 12 hours.
This schedule is appropriate for general configuration-change tracking. Use a shorter interval when faster detection is required, while considering:
|
Consideration |
|---|
|
Salesforce API consumption |
|
Number of monitored organizations |
|
Audit-event volume |
|
Required alerting speed |
|
GermainUX processing and storage |
For immediate security or activity detection, Salesforce Real-Time Event Monitoring may also be required because scheduled audit collection is not designed as a real-time security feed.
🔧 Configure the Frequency During Deployment
During the initial Salesforce Application wizard:
-
Select Show Advanced.
-
Locate Audit Monitoring Interval.
-
Enter the required frequency.
-
Complete the wizard.
🔁 Change the Frequency After Deployment
To update the schedule of an existing audit monitor:
-
Open GermainUX Workspace.
-
Open the left navigation menu.
-
Select Germain.
-
Open the State tab.
-
Search for:
Type Name = Salesforce Audit Monitor
Salesforce Audit Monitoring component -
Select the monitor associated with the intended Salesforce organization.
-
Update Execution Schedule.
-
Save the change.
The revised schedule applies to subsequent executions.
⛔ Disable Audit Monitoring
To stop ongoing collection without removing the entire Salesforce integration:
-
Open GermainUX Workspace.
-
Open the left navigation menu.
-
Select Germain.
-
Open the State tab.
-
Search for:
Type Name = Salesforce Audit Monitor -
Locate the appropriate monitor.
-
Turn off the toggle in the Enabled column.
-
Save the change if prompted.
Disabling the monitor stops future collection. Previously collected audit records remain available according to the applicable GermainUX retention policy.
▶️ Re-enable Audit Monitoring
To resume collection:
-
Return to Germain → State.
-
Search for
Salesforce Audit Monitor. -
Turn on the Enabled toggle.
-
Confirm the execution schedule.
-
Save the configuration.
-
Allow the next scheduled execution to run.
📊 View Salesforce Audit Data
Open:
Dashboards → IT → Application → Salesforce → Salesforce
Review the portlets related to Audit.
The dashboard can help analyze:
|
Analysis |
|---|
|
Recent Salesforce changes |
|
Changes by administrator |
|
Change categories |
|
Affected components |
|
Change frequency |
|
Changes by organization or environment |
|
Configuration activity preceding an issue |
Select an audit metric or record to open its details and related evidence.
🎯 Salesforce Audit KPIs
See Salesforce Audit KPIs.
These KPIs can be used to:
|
KPI |
|---|
|
Count configuration changes |
|
Track trends |
|
Segment changes by administrator or category |
|
Identify unusual administrative activity |
|
Compare environments |
|
Correlate changes with application regressions |
🔗 Correlate Changes With Salesforce Issues
Audit data becomes particularly useful when analyzed alongside other Salesforce telemetry.
For example:
-
Salesforce response time degrades.
-
GermainUX identifies when the degradation began.
-
Audit records show that a Flow, Apex class, permission, or integration setting changed shortly beforehand.
-
Related errors, debug logs, user sessions, and Session Replay provide additional evidence.
-
The team confirms whether the change caused or contributed to the regression.
Audit records can be correlated with:
-
Apex exceptions
-
Debug logs
-
Salesforce errors
-
API and integration failures
-
User-facing errors
-
Slow interactions
-
Failed workflows
-
Session Replay
-
Salesforce deployments
-
Instance-status events
A temporal correlation is evidence for investigation, but it does not by itself prove causation.
🔔 Configure Alerts
Create alerts for audit activity that requires timely review.
Useful alert conditions include:
-
A critical Salesforce configuration changes.
-
A high-risk security setting changes.
-
A Connected App or OAuth configuration changes.
-
A user, profile, or permission changes unexpectedly.
-
Multiple administrative changes occur within a short period.
-
A change occurs outside an approved maintenance window.
-
A new performance or error regression follows a configuration change.
-
An unauthorized or unexpected administrator performs a change.
Alert recipients may include:
-
Salesforce administrators
-
Security teams
-
Application owners
-
Operations teams
-
Change-management teams
Avoid generating an alert for every routine change. Categorize and prioritize changes according to their operational and security significance.
📋 Validate Audit Monitoring
After the first scheduled execution, verify that:
-
Salesforce Audit Monitoris enabled. -
Its last execution completed successfully.
-
Its next execution matches the configured schedule.
-
Audit records appear in the Salesforce dashboard.
-
The correct organization and environment are assigned.
-
Timestamps and administrator identities are accurate.
-
Expected configuration changes are present.
-
Details are sufficient for investigation.
-
Alerts fire only for the intended conditions.
For controlled validation:
-
Make a harmless, approved configuration change in a non-production Salesforce environment.
-
Wait for the next monitor execution.
-
Confirm that the change appears in GermainUX.
-
Verify its user, timestamp, action, and organization.
-
Reverse the test change if appropriate.
❓ No Audit Data Appears
If the monitor runs but no audit records appear:
-
Confirm that the correct Salesforce organization is configured.
-
Verify the OAuth connection.
-
Confirm that the integration user can access Salesforce audit information.
-
Check that
Salesforce Audit Monitoris enabled. -
Review its last execution and next scheduled execution.
-
Confirm that the selected GermainUX Engine is running.
-
Check connectivity from the Engine to Salesforce.
-
Review Engine logs for authentication, authorization, API, and parsing errors.
-
Check Salesforce API usage and limits.
-
Confirm that audit records exist for the selected time range.
-
Verify dashboard filters, organization, environment, and timezone.
⏳ Audit Data Is Delayed
Audit Monitoring is scheduled rather than instantaneous.
If records arrive later than required:
-
Review the current Execution Schedule.
-
Confirm that recent executions completed successfully.
-
Reduce the interval if faster collection is operationally justified.
-
Review the effect on Salesforce API consumption.
-
Consider Real-Time Event Monitoring for use cases requiring immediate detection.
🔒 Security and Retention
Audit records can contain sensitive information about:
-
Administrators
-
Security configuration
-
Permissions
-
Connected Apps
-
Internal components
-
Integration endpoints
-
Organizational changes
Before production use:
-
Limit access to audit dashboards and records.
-
Use a dedicated Salesforce integration account.
-
Grant only required permissions.
-
Protect user and administrator identifiers.
-
Configure appropriate retention.
-
Align alerts with incident-response and change-management procedures.
-
Avoid exposing credentials, secrets, or OAuth tokens.
📚 Related Documentation
ℹ️ Get More Information
GermainUX can help determine which monitoring, analytics and automation capabilities are appropriate for your Salesforce CRM environment.
Component: Engine, JS Profiler, Mobile App, RPA Bot Recorder, RUM Ext
Feature Availability: 2017.1 or later