Real-Time Event Monitoring for Salesforce Cloud (Configure)

⚙️ Configure Salesforce Real-Time Event Monitoring

GermainUX subscribes to Salesforce Real-Time Event Monitoring streams and converts supported Salesforce events into KPIs for security, compliance, operational, and user-activity analysis.

Real-Time Event Monitoring helps teams:

  • Detect high-risk user behavior

  • Monitor access to sensitive data

  • Analyze API activity and anomalies

  • Track report exports and file downloads

  • Detect suspicious login or session activity

  • Monitor record access and changes

  • Identify Salesforce limit and execution errors

  • Alert security and operations teams as events occur

The monitoring is performed by the GermainUX Engine.

✅ What Can Be Monitored

Available events depend on the Salesforce organization’s edition, licenses, enabled features, event topics, and integration-user permissions.

🔐 Authentication and Session Security

GermainUX can process available events related to:

  • Login attempts under defined conditions

  • Successful logins during a suspected credential-stuffing attack

  • User logout through the Salesforce interface

  • Session hijacking or use of stolen session identifiers

  • Administrators logging in as other users

  • Activities performed during delegated or impersonated sessions

📁 Sensitive Data Access

Available events can help detect when users:

  • Query sensitive records

  • Access sensitive objects or fields

  • Create, update, or delete sensitive records

  • Access or export list-view data

  • Run or export reports containing sensitive data

  • Download files

  • Use APIs to retrieve sensitive information

🛰️ API Activity

GermainUX can monitor available events involving:

  • API calls

  • Unusual API-call patterns

  • Bulk API operations

  • Bulk API result downloads

  • Abnormal API volume

  • API errors

  • API activity by user, client, or connected application

📊 Reports and Exports

Available report events can help identify when users:

  • Create reports

  • Run reports

  • Modify reports

  • Export report results

  • Access reports containing sensitive data

  • Exhibit unusual report-execution or export behavior

✨ Records and Lightning Activity

Available events can include:

  • Lightning record access

  • Record creation

  • Record updates

  • Record deletion

  • List-view access

  • List-view exports

  • Other supported record activity

🛠️ Permissions and Administration

GermainUX can monitor supported events involving:

  • Permission assignments

  • Permission-set changes

  • Permission-set-group changes

  • Administrative access

  • Security-related configuration activity

For broader scheduled configuration tracking, also use Salesforce Audit Monitoring.

📱 Salesforce Mobile Activity

When Salesforce exposes the applicable events, GermainUX can monitor supported mobile activity such as:

  • Email actions

  • Phone calls

  • Text messages

  • Screenshot-related activity

  • Other Salesforce mobile actions

warning Limits and Operational Errors

GermainUX can detect supported events associated with Salesforce execution problems, such as exceeding the concurrent long-running Apex-request limit.

📋 Prerequisites

Before configuring Real-Time Event Monitoring, confirm that:

  • A GermainUX Engine is deployed and running.

  • Salesforce monitoring has been deployed through the Salesforce Application wizard.

  • The Salesforce OAuth connection is active.

  • The integration user has API access.

  • The integration user can subscribe to the required event topics.

  • Required Salesforce Event Monitoring features and licenses are available.

  • The Engine can maintain outbound connectivity to Salesforce.

  • Network devices allow the long-lived connection required by event streaming.

  • The selected topics are approved by security and privacy teams.

Not every Salesforce organization exposes every event type. Confirm availability with the Salesforce administrator before designing dashboards or alerts around a specific topic.

▶️ Enable Real-Time Event Monitoring

Real-Time Event Monitoring is enabled automatically when Salesforce monitoring is deployed through the Salesforce Application wizard.

To deploy it:

  1. Open GermainUX Workspace.

  2. Open the left navigation menu.

  3. Select Wizards.

  4. Select Salesforce Application.

  5. Choose the GermainUX Engine that will receive the events.

  6. Enter the Salesforce OAuth and organization settings.

  7. Complete the wizard.

  8. Confirm that the Salesforce event-monitoring component is enabled.

The component is identified as:

Salesforce Event Monitoring


🔁 How Real-Time Collection Differs From Scheduled Monitoring

Real-Time Event Monitoring maintains event-stream subscriptions instead of periodically polling Salesforce on an hourly or daily schedule.

Monitoring type

Collection model

Real-Time Event Monitoring

Receives events from enabled Salesforce topics as Salesforce publishes them

Audit Monitoring

Periodically retrieves administrative and configuration changes

Debug Log Monitoring

Periodically retrieves generated Salesforce Debug Logs

Instance Status Monitoring

Periodically checks the published status of the Salesforce instance

Real-time means that GermainUX processes the event shortly after it becomes available from Salesforce. It does not guarantee zero latency; delivery depends on Salesforce event publication, network connectivity, and processing.

⚙️ Configure Event Topics

The Salesforce Event Monitor subscribes to a configured list of topics.

Enable only the topics required for the intended use cases because each topic can affect:

  • Event volume

  • Salesforce entitlements

  • GermainUX ingestion

  • Storage requirements

  • Privacy exposure

  • Alert volume

Typical categories include:

  • API events

  • Login and logout events

  • Report events

  • File events

  • Record events

  • Lightning events

  • Permission events

  • Session-security events

  • Mobile events

The exact topic names depend on the Salesforce services and GermainUX version.

⛔ Disable an Event Topic

To stop collecting an individual topic while leaving the monitor active:

  1. Open GermainUX Workspace.

  2. Open the left navigation menu.

  3. Navigate to:

    System → Engine → Component Types

  4. Search for:

    Name = Salesforce Event Monitor
    
  5. Open the component type.

  6. Locate Topics.

  7. Remove the topic that should no longer be monitored.

  8. Save the configuration.

  9. Restart or refresh the applicable component if required.

  10. Confirm that events from the removed topic no longer arrive.

Record the previous topic list before editing it so the configuration can be restored if needed.

Editing the component type may affect every monitor using that type. Confirm the scope before removing a topic.

➕ Add or Restore an Event Topic

To add or restore a topic:

  1. Confirm that the Salesforce organization exposes the topic.

  2. Confirm that the integration user can subscribe to it.

  3. Open the Salesforce Event Monitor component type.

  4. Add the exact supported topic name to Topics.

  5. Save the configuration.

  6. Restart or refresh the component if required.

  7. Generate a controlled test event.

  8. Confirm that it appears in GermainUX.

Do not invent or approximate topic names. Use only event topics supported by both Salesforce and the installed GermainUX version.

⏹️ Disable Real-Time Event Monitoring

To stop all Salesforce real-time event collection:

  1. Open GermainUX Workspace.

  2. Open the left navigation menu.

  3. Select Germain.

  4. Open the State tab.

  5. Search for:

    Name = Salesforce Event Monitoring
    
  6. Locate the component associated with the intended Salesforce organization.

  7. Turn off the toggle in the Enabled column.

  8. Save the change if prompted.

Previously collected events remain available according to the configured retention policy.

🔁 Re-enable Monitoring

To resume all configured event subscriptions:

  1. Return to Germain → State.

  2. Search for Salesforce Event Monitoring.

  3. Turn on the Enabled toggle.

  4. Confirm that the OAuth connection is valid.

  5. Confirm the configured topic list.

  6. Save the configuration.

  7. Verify that new events arrive.

👀 View Real-Time Events

Open:

GermainUX Workspace → Dashboards → All → Salesforce RT Events

The dashboard can provide:

  • Event volume

  • Event trends

  • API events

  • Login and logout activity

  • Lightning record events

  • Report execution and export events

  • Record-change events

  • Security-relevant activity

  • Access to individual event details

Select an event or KPI to drill through to its attributes and related evidence.

📊 Salesforce Real-Time Event KPIs

See Salesforce Real-Time Event KPIs.

Depending on the event type, useful measures include:

  • Event count

  • Unique users

  • Unique sessions

  • Unique records

  • Unique reports

  • Unique API clients

  • Error count

  • Failure rate

  • Data volume

  • Duration

  • Risk or severity

Useful pivots may include:

  • Event type

  • User

  • Profile

  • Permission

  • IP address

  • Session

  • API client

  • Connected App

  • Report

  • Record

  • Object

  • Operation

  • Salesforce organization

  • Environment

  • Result or status

🔔 Configure Alerts

Real-Time Event Monitoring is particularly valuable when events require immediate review.

🛡️ Security Alerts

Examples include:

  • Successful login during a credential-stuffing attack

  • Suspected session hijacking

  • Sensitive-data access by an unauthorized user

  • Unusual API behavior

  • Unexpected Bulk API result download

  • High-volume file download

  • Administrator login as another user

  • Unexpected permission assignment

  • Report export containing sensitive data

🔧 Operational Alerts

Examples include:

  • Concurrent long-running Apex limit exceeded

  • Repeated API errors

  • Real-time event stream disconnected

  • No events received when activity is expected

  • Event volume deviates substantially from baseline

  • A previously unseen event or error category appears

Configure thresholds and categorization to avoid sending an alert for every routine event.

🔗 Correlate Events With Other Evidence

Real-Time Events become more useful when correlated with:

  • Salesforce user sessions

  • Session Replay

  • User clicks and navigation

  • Apex exceptions

  • Debug Logs

  • API and integration activity

  • Audit changes

  • User-facing errors

  • Business-process activity

For example:

  1. A report-export event identifies a user exporting sensitive data.

  2. Browser monitoring identifies the Salesforce session.

  3. Session Replay shows the navigation and actions leading to the export.

  4. Audit data reveals a recent permission change.

  5. GermainUX alerts the security team with the related evidence.

Correlation depends on the identifiers available across the event sources.

✅ Validate Real-Time Event Monitoring

Test each required topic separately.

  1. Confirm that Salesforce Event Monitoring is enabled.

  2. Confirm that the Engine is connected to Salesforce.

  3. Verify the OAuth authorization and permissions.

  4. Review the configured topics.

  5. Generate a safe test event in a non-production environment.

  6. Open Salesforce RT Events.

  7. Confirm that the event appears.

  8. Verify its event type, user, timestamp, organization, and result.

  9. Test the applicable categorization.

  10. Confirm that any alert is triggered and routed correctly.

Use controlled tests that comply with organizational security policies. Do not simulate an actual credential attack or unauthorized access.

❌ No Real-Time Events Appear

If events are missing:

  1. Confirm that the Salesforce organization supports the event topic.

  2. Verify that the required Salesforce feature or license is active.

  3. Confirm that the integration user can subscribe to the topic.

  4. Verify the Salesforce OAuth connection.

  5. Check that Salesforce Event Monitoring is enabled.

  6. Confirm that the topic remains in the configured Topics list.

  7. Verify that the GermainUX Engine is running.

  8. Check Engine connectivity to Salesforce.

  9. Review Engine logs for authentication, subscription, network, and parsing errors.

  10. Confirm that a matching event occurred during the selected time range.

  11. Review dashboard organization, environment, and event-type filters.

  12. Check applicable Salesforce event-delivery entitlements and limits.

❓ Only Some Event Types Appear

If some topics work and others do not:

  • Verify Salesforce support and licensing for each missing topic.

  • Check permissions for the integration user.

  • Confirm the exact topic name.

  • Verify the topic is present in Topics.

  • Generate a known event of that type.

  • Review Engine logs for topic-specific subscription errors.

  • Confirm that the dashboard includes the corresponding KPI.

⏱️ Event Delivery Stops

If events appeared previously but stop arriving:

  1. Confirm that the Engine is running.

  2. Verify network connectivity.

  3. Check whether the OAuth token expired or was revoked.

  4. Confirm that the Connected App remains authorized.

  5. Review subscription and reconnection errors.

  6. Confirm that Salesforce still exposes the topic.

  7. Check Salesforce service status.

  8. Validate with a controlled test event.

  9. Restart the monitor if required.

Configure a health alert for interrupted or stale event streams when continuous collection is critical.

💾 Data Volume and Retention

Real-time event streams can generate substantial data.

Before enabling many topics:

  • Estimate expected event volume.

  • Enable only required topics.

  • Configure appropriate retention.

  • Monitor Salesforce delivery entitlements.

  • Monitor GermainUX ingestion and storage.

  • Categorize repetitive events.

  • Exclude non-actionable data.

  • Review high-volume topics after deployment.

🔒 Security and Privacy

Real-time events can contain sensitive security and activity information, including:

  • User identities

  • IP addresses

  • Session identifiers

  • Record and object identifiers

  • Report names

  • File activity

  • API clients

  • Permission changes

  • Security-event details

Before production enablement:

  • Use a dedicated least-privilege integration account.

  • Restrict access to event dashboards and details.

  • Mask, anonymize, or exclude sensitive fields.

  • Never retain credentials, secrets, OAuth tokens, or reusable session identifiers.

  • Apply appropriate retention.

  • Review event use cases with Salesforce, security, privacy, and compliance owners.

ℹ️ Get Help

The Germain Team can help you set this up. Contact GermainUX Support.

Component: Engine

Feature Availability: 2017.1 or later