⚙️ Configure Salesforce Real-Time Event Monitoring
GermainUX subscribes to Salesforce Real-Time Event Monitoring streams and converts supported Salesforce events into KPIs for security, compliance, operational, and user-activity analysis.
Real-Time Event Monitoring helps teams:
|
Capability |
|---|
|
Detect high-risk user behavior |
|
Monitor access to sensitive data |
|
Analyze API activity and anomalies |
|
Track report exports and file downloads |
|
Detect suspicious login or session activity |
|
Monitor record access and changes |
|
Identify Salesforce limit and execution errors |
|
Alert security and operations teams as events occur |
The monitoring is performed by the GermainUX Engine.
✅ What Can Be Monitored
Available events depend on the Salesforce organization’s edition, licenses, enabled features, event topics, and integration-user permissions.
🔐 Authentication and Session Security
GermainUX can process available events related to:
|
Event |
|---|
|
Login attempts under defined conditions |
|
Successful logins during a suspected credential-stuffing attack |
|
User logout through the Salesforce interface |
|
Session hijacking or use of stolen session identifiers |
|
Administrators logging in as other users |
|
Activities performed during delegated or impersonated sessions |
📁 Sensitive Data Access
Available events can help detect when users:
|
Action |
|---|
|
Query sensitive records |
|
Access sensitive objects or fields |
|
Create, update, or delete sensitive records |
|
Access or export list-view data |
|
Run or export reports containing sensitive data |
|
Download files |
|
Use APIs to retrieve sensitive information |
🛰️ API Activity
GermainUX can monitor available events involving:
|
Event |
|---|
|
API calls |
|
Unusual API-call patterns |
|
Bulk API operations |
|
Bulk API result downloads |
|
Abnormal API volume |
|
API errors |
|
API activity by user, client, or connected application |
📊 Reports and Exports
Available report events can help identify when users:
|
Action |
|---|
|
Create reports |
|
Run reports |
|
Modify reports |
|
Export report results |
|
Access reports containing sensitive data |
|
Exhibit unusual report-execution or export behavior |
✨ Records and Lightning Activity
Available events can include:
|
Event |
|---|
|
Lightning record access |
|
Record creation |
|
Record updates |
|
Record deletion |
|
List-view access |
|
List-view exports |
|
Other supported record activity |
🛠️ Permissions and Administration
GermainUX can monitor supported events involving:
|
Event |
|---|
|
Permission assignments |
|
Permission-set changes |
|
Permission-set-group changes |
|
Administrative access |
|
Security-related configuration activity |
For broader scheduled configuration tracking, also use Salesforce Audit Monitoring.
📱 Salesforce Mobile Activity
When Salesforce exposes the applicable events, GermainUX can monitor supported mobile activity such as:
|
Mobile Action |
|---|
|
Email actions |
|
Phone calls |
|
Text messages |
|
Screenshot-related activity |
|
Other Salesforce mobile actions |
Limits and Operational Errors
GermainUX can detect supported events associated with Salesforce execution problems, such as exceeding the concurrent long-running Apex-request limit.
📋 Prerequisites
Before configuring Real-Time Event Monitoring, confirm that:
|
Requirement |
|---|
|
A GermainUX Engine is deployed and running. |
|
Salesforce monitoring has been deployed through the Salesforce Application wizard. |
|
The Salesforce OAuth connection is active. |
|
The integration user has API access. |
|
The integration user can subscribe to the required event topics. |
|
Required Salesforce Event Monitoring features and licenses are available. |
|
The Engine can maintain outbound connectivity to Salesforce. |
|
Network devices allow the long-lived connection required by event streaming. |
|
The selected topics are approved by security and privacy teams. |
Not every Salesforce organization exposes every event type. Confirm availability with the Salesforce administrator before designing dashboards or alerts around a specific topic.
▶️ Enable Real-Time Event Monitoring
Real-Time Event Monitoring is enabled automatically when Salesforce monitoring is deployed through the Salesforce Application wizard.
To deploy it:
-
Open GermainUX Workspace.
-
Open the left navigation menu.
-
Select Wizards.
-
Select Salesforce Application.
-
Choose the GermainUX Engine that will receive the events.
-
Enter the Salesforce OAuth and organization settings.
-
Complete the wizard.
-
Confirm that the Salesforce event-monitoring component is enabled.
The component is identified as:
Salesforce Event Monitoring
🔁 How Real-Time Collection Differs From Scheduled Monitoring
Real-Time Event Monitoring maintains event-stream subscriptions instead of periodically polling Salesforce on an hourly or daily schedule.
|
Monitoring type |
Collection model |
|---|---|
|
Real-Time Event Monitoring |
Receives events from enabled Salesforce topics as Salesforce publishes them |
|
Audit Monitoring |
Periodically retrieves administrative and configuration changes |
|
Debug Log Monitoring |
Periodically retrieves generated Salesforce Debug Logs |
|
Instance Status Monitoring |
Periodically checks the published status of the Salesforce instance |
Real-time means that GermainUX processes the event shortly after it becomes available from Salesforce. It does not guarantee zero latency; delivery depends on Salesforce event publication, network connectivity, and processing.
⚙️ Configure Event Topics
The Salesforce Event Monitor subscribes to a configured list of topics.
Enable only the topics required for the intended use cases because each topic can affect:
|
Impact |
Details |
|---|---|
|
Event volume |
Event volume |
|
Salesforce entitlements |
Salesforce entitlements |
|
GermainUX ingestion |
GermainUX ingestion |
|
Storage requirements |
Storage requirements |
|
Privacy exposure |
Privacy exposure |
|
Alert volume |
Alert volume |
Typical categories include:
|
Category |
Examples |
|---|---|
|
API events |
API events |
|
Login and logout events |
Login and logout events |
|
Report events |
Report events |
|
File events |
File events |
|
Record events |
Record events |
|
Lightning events |
Lightning events |
|
Permission events |
Permission events |
|
Session-security events |
Session-security events |
|
Mobile events |
Mobile events |
The exact topic names depend on the Salesforce services and GermainUX version.
⛔ Disable an Event Topic
To stop collecting an individual topic while leaving the monitor active:
-
Open GermainUX Workspace.
-
Open the left navigation menu.
-
Navigate to:
System → Engine → Component Types
-
Search for:
Name = Salesforce Event Monitor -
Open the component type.
-
Locate Topics.
-
Remove the topic that should no longer be monitored.
-
Save the configuration.
-
Restart or refresh the applicable component if required.
-
Confirm that events from the removed topic no longer arrive.
Record the previous topic list before editing it so the configuration can be restored if needed.
Editing the component type may affect every monitor using that type. Confirm the scope before removing a topic.
➕ Add or Restore an Event Topic
To add or restore a topic:
-
Confirm that the Salesforce organization exposes the topic.
-
Confirm that the integration user can subscribe to it.
-
Open the
Salesforce Event Monitorcomponent type. -
Add the exact supported topic name to Topics.
-
Save the configuration.
-
Restart or refresh the component if required.
-
Generate a controlled test event.
-
Confirm that it appears in GermainUX.
Do not invent or approximate topic names. Use only event topics supported by both Salesforce and the installed GermainUX version.
⏹️ Disable Real-Time Event Monitoring
To stop all Salesforce real-time event collection:
-
Open GermainUX Workspace.
-
Open the left navigation menu.
-
Select Germain.
-
Open the State tab.
-
Search for:
Name = Salesforce Event Monitoring -
Locate the component associated with the intended Salesforce organization.
-
Turn off the toggle in the Enabled column.
-
Save the change if prompted.
Previously collected events remain available according to the configured retention policy.
🔁 Re-enable Monitoring
To resume all configured event subscriptions:
-
Return to Germain → State.
-
Search for
Salesforce Event Monitoring. -
Turn on the Enabled toggle.
-
Confirm that the OAuth connection is valid.
-
Confirm the configured topic list.
-
Save the configuration.
-
Verify that new events arrive.
👀 View Real-Time Events
Open:
GermainUX Workspace → Dashboards → All → Salesforce RT Events
The dashboard can provide:
|
View |
Details |
|---|---|
|
Event volume |
Event volume |
|
Event trends |
Event trends |
|
API events |
API events |
|
Login and logout activity |
Login and logout activity |
|
Lightning record events |
Lightning record events |
|
Report execution and export events |
Report execution and export events Unknown Attachment |
|
Record-change events |
Record-change events Unknown Attachment |
|
Security-relevant activity |
Security-relevant activity |
|
Access to individual event details |
Access to individual event details |
Select an event or KPI to drill through to its attributes and related evidence.
Unknown Attachment
📊 Salesforce Real-Time Event KPIs
See Salesforce Real-Time Event KPIs.
Depending on the event type, useful measures include:
|
Measure |
Details |
|---|---|
|
Event count |
Event count |
|
Unique users |
Unique users |
|
Unique sessions |
Unique sessions |
|
Unique records |
Unique records |
|
Unique reports |
Unique reports |
|
Unique API clients |
Unique API clients |
|
Error count |
Error count |
|
Failure rate |
Failure rate |
|
Data volume |
Data volume |
|
Duration |
Duration |
|
Risk or severity |
Risk or severity |
Useful pivots may include:
|
Pivot |
Details |
|---|---|
|
Event type |
Event type |
|
User |
User |
|
Profile |
Profile |
|
Permission |
Permission |
|
IP address |
IP address |
|
Session |
Session |
|
API client |
API client |
|
Connected App |
Connected App |
|
Report |
Report |
|
Record |
Record |
|
Object |
Object |
|
Operation |
Operation |
|
Salesforce organization |
Salesforce organization |
|
Environment |
Environment |
|
Result or status |
Result or status |
🔔 Configure Alerts
Real-Time Event Monitoring is particularly valuable when events require immediate review.
🛡️ Security Alerts
Examples include:
|
Alert |
Details |
|---|---|
|
Successful login during a credential-stuffing attack |
Successful login during a credential-stuffing attack |
|
Suspected session hijacking |
Suspected session hijacking |
|
Sensitive-data access by an unauthorized user |
Sensitive-data access by an unauthorized user |
|
Unusual API behavior |
Unusual API behavior |
|
Unexpected Bulk API result download |
Unexpected Bulk API result download |
|
High-volume file download |
High-volume file download |
|
Administrator login as another user |
Administrator login as another user |
|
Unexpected permission assignment |
Unexpected permission assignment |
|
Report export containing sensitive data |
Report export containing sensitive data |
🔧 Operational Alerts
Examples include:
|
Alert |
Details |
|---|---|
|
Concurrent long-running Apex limit exceeded |
Concurrent long-running Apex limit exceeded |
|
Repeated API errors |
Repeated API errors |
|
Real-time event stream disconnected |
Real-time event stream disconnected |
|
No events received when activity is expected |
No events received when activity is expected |
|
Event volume deviates substantially from baseline |
Event volume deviates substantially from baseline |
|
A previously unseen event or error category appears |
A previously unseen event or error category appears |
Configure thresholds and categorization to avoid sending an alert for every routine event.
🔗 Correlate Events With Other Evidence
Real-Time Events become more useful when correlated with:
|
Evidence |
Details |
|---|---|
|
Salesforce user sessions |
Salesforce user sessions |
|
Session Replay |
Session Replay |
|
User clicks and navigation |
User clicks and navigation |
|
Apex exceptions |
Apex exceptions |
|
Debug Logs |
Debug Logs |
|
API and integration activity |
API and integration activity |
|
Audit changes |
Audit changes |
|
User-facing errors |
User-facing errors |
|
Business-process activity |
Business-process activity |
For example:
-
A report-export event identifies a user exporting sensitive data.
-
Browser monitoring identifies the Salesforce session.
-
Session Replay shows the navigation and actions leading to the export.
-
Audit data reveals a recent permission change.
-
GermainUX alerts the security team with the related evidence.
Correlation depends on the identifiers available across the event sources.
✅ Validate Real-Time Event Monitoring
Test each required topic separately.
-
Confirm that
Salesforce Event Monitoringis enabled. -
Confirm that the Engine is connected to Salesforce.
-
Verify the OAuth authorization and permissions.
-
Review the configured topics.
-
Generate a safe test event in a non-production environment.
-
Open Salesforce RT Events.
-
Confirm that the event appears.
-
Verify its event type, user, timestamp, organization, and result.
-
Test the applicable categorization.
-
Confirm that any alert is triggered and routed correctly.
Use controlled tests that comply with organizational security policies. Do not simulate an actual credential attack or unauthorized access.
❌ No Real-Time Events Appear
If events are missing:
-
Confirm that the Salesforce organization supports the event topic.
-
Verify that the required Salesforce feature or license is active.
-
Confirm that the integration user can subscribe to the topic.
-
Verify the Salesforce OAuth connection.
-
Check that
Salesforce Event Monitoringis enabled. -
Confirm that the topic remains in the configured Topics list.
-
Verify that the GermainUX Engine is running.
-
Check Engine connectivity to Salesforce.
-
Review Engine logs for authentication, subscription, network, and parsing errors.
-
Confirm that a matching event occurred during the selected time range.
-
Review dashboard organization, environment, and event-type filters.
-
Check applicable Salesforce event-delivery entitlements and limits.
❓ Only Some Event Types Appear
If some topics work and others do not:
-
Verify Salesforce support and licensing for each missing topic.
-
Check permissions for the integration user.
-
Confirm the exact topic name.
-
Verify the topic is present in Topics.
-
Generate a known event of that type.
-
Review Engine logs for topic-specific subscription errors.
-
Confirm that the dashboard includes the corresponding KPI.
⏱️ Event Delivery Stops
If events appeared previously but stop arriving:
-
Confirm that the Engine is running.
-
Verify network connectivity.
-
Check whether the OAuth token expired or was revoked.
-
Confirm that the Connected App remains authorized.
-
Review subscription and reconnection errors.
-
Confirm that Salesforce still exposes the topic.
-
Check Salesforce service status.
-
Validate with a controlled test event.
-
Restart the monitor if required.
Configure a health alert for interrupted or stale event streams when continuous collection is critical.
💾 Data Volume and Retention
Real-time event streams can generate substantial data.
Before enabling many topics:
-
Estimate expected event volume.
-
Enable only required topics.
-
Configure appropriate retention.
-
Monitor Salesforce delivery entitlements.
-
Monitor GermainUX ingestion and storage.
-
Categorize repetitive events.
-
Exclude non-actionable data.
-
Review high-volume topics after deployment.
🔒 Security and Privacy
Real-time events can contain sensitive security and activity information, including:
|
Sensitive Data |
Details |
|---|---|
|
User identities |
User identities |
|
IP addresses |
IP addresses |
|
Session identifiers |
Session identifiers |
|
Record and object identifiers |
Record and object identifiers |
|
Report names |
Report names |
|
File activity |
File activity |
|
API clients |
API clients |
|
Permission changes |
Permission changes |
|
Security-event details |
Security-event details |
Before production enablement:
-
Use a dedicated least-privilege integration account.
-
Restrict access to event dashboards and details.
-
Mask, anonymize, or exclude sensitive fields.
-
Never retain credentials, secrets, OAuth tokens, or reusable session identifiers.
-
Apply appropriate retention.
-
Review event use cases with Salesforce, security, privacy, and compliance owners.
📚 Related Documentation
|
Document |
Link |
|---|---|
|
Salesforce Monitoring Configuration |
https://docs.germainux.com/main/salesforce-monitoring-configuration |
|
Apex Code Monitoring |
|
|
Salesforce Debug Log Monitoring |
https://docs.germainux.com/main/salesforce-debug-log-monitoring |
|
Salesforce Error Monitoring |
https://docs.germainux.com/main/error-monitoring-for-salesforce-cloud-configure |
|
User Monitoring and Session Replay |
https://docs.germainux.com/main/salesforce-user-monitoring-and-replay |
|
Salesforce Monitoring KPIs |
ℹ️ Get More Information
GermainUX can help determine which monitoring, analytics and automation capabilities are appropriate for your Salesforce CRM environment.
Component: Engine, JS Profiler, Mobile App, RPA Bot Recorder, RUM Ext
Feature Availability: 2017.1 or later