Real-Time Event Monitoring for Salesforce Cloud (Configure)

⚙️ Configure Salesforce Real-Time Event Monitoring

GermainUX subscribes to Salesforce Real-Time Event Monitoring streams and converts supported Salesforce events into KPIs for security, compliance, operational, and user-activity analysis.

Real-Time Event Monitoring helps teams:

Capability

Detect high-risk user behavior

Monitor access to sensitive data

Analyze API activity and anomalies

Track report exports and file downloads

Detect suspicious login or session activity

Monitor record access and changes

Identify Salesforce limit and execution errors

Alert security and operations teams as events occur

The monitoring is performed by the GermainUX Engine.

✅ What Can Be Monitored

Available events depend on the Salesforce organization’s edition, licenses, enabled features, event topics, and integration-user permissions.

🔐 Authentication and Session Security

GermainUX can process available events related to:

Event

Login attempts under defined conditions

Successful logins during a suspected credential-stuffing attack

User logout through the Salesforce interface

Session hijacking or use of stolen session identifiers

Administrators logging in as other users

Activities performed during delegated or impersonated sessions

📁 Sensitive Data Access

Available events can help detect when users:

Action

Query sensitive records

Access sensitive objects or fields

Create, update, or delete sensitive records

Access or export list-view data

Run or export reports containing sensitive data

Download files

Use APIs to retrieve sensitive information

🛰️ API Activity

GermainUX can monitor available events involving:

Event

API calls

Unusual API-call patterns

Bulk API operations

Bulk API result downloads

Abnormal API volume

API errors

API activity by user, client, or connected application

📊 Reports and Exports

Available report events can help identify when users:

Action

Create reports

Run reports

Modify reports

Export report results

Access reports containing sensitive data

Exhibit unusual report-execution or export behavior

✨ Records and Lightning Activity

Available events can include:

Event

Lightning record access

Record creation

Record updates

Record deletion

List-view access

List-view exports

Other supported record activity

🛠️ Permissions and Administration

GermainUX can monitor supported events involving:

Event

Permission assignments

Permission-set changes

Permission-set-group changes

Administrative access

Security-related configuration activity

For broader scheduled configuration tracking, also use Salesforce Audit Monitoring.

📱 Salesforce Mobile Activity

When Salesforce exposes the applicable events, GermainUX can monitor supported mobile activity such as:

Mobile Action

Email actions

Phone calls

Text messages

Screenshot-related activity

Other Salesforce mobile actions

warning Limits and Operational Errors

GermainUX can detect supported events associated with Salesforce execution problems, such as exceeding the concurrent long-running Apex-request limit.

📋 Prerequisites

Before configuring Real-Time Event Monitoring, confirm that:

Requirement

A GermainUX Engine is deployed and running.

Salesforce monitoring has been deployed through the Salesforce Application wizard.

The Salesforce OAuth connection is active.

The integration user has API access.

The integration user can subscribe to the required event topics.

Required Salesforce Event Monitoring features and licenses are available.

The Engine can maintain outbound connectivity to Salesforce.

Network devices allow the long-lived connection required by event streaming.

The selected topics are approved by security and privacy teams.

Not every Salesforce organization exposes every event type. Confirm availability with the Salesforce administrator before designing dashboards or alerts around a specific topic.

▶️ Enable Real-Time Event Monitoring

Real-Time Event Monitoring is enabled automatically when Salesforce monitoring is deployed through the Salesforce Application wizard.

To deploy it:

  1. Open GermainUX Workspace.

  2. Open the left navigation menu.

  3. Select Wizards.

  4. Select Salesforce Application.

  5. Choose the GermainUX Engine that will receive the events.

  6. Enter the Salesforce OAuth and organization settings.

  7. Complete the wizard.

  8. Confirm that the Salesforce event-monitoring component is enabled.

The component is identified as:

Salesforce Event Monitoring


🔁 How Real-Time Collection Differs From Scheduled Monitoring

Real-Time Event Monitoring maintains event-stream subscriptions instead of periodically polling Salesforce on an hourly or daily schedule.

Monitoring type

Collection model

Real-Time Event Monitoring

Receives events from enabled Salesforce topics as Salesforce publishes them

Audit Monitoring

Periodically retrieves administrative and configuration changes

Debug Log Monitoring

Periodically retrieves generated Salesforce Debug Logs

Instance Status Monitoring

Periodically checks the published status of the Salesforce instance

Real-time means that GermainUX processes the event shortly after it becomes available from Salesforce. It does not guarantee zero latency; delivery depends on Salesforce event publication, network connectivity, and processing.

⚙️ Configure Event Topics

The Salesforce Event Monitor subscribes to a configured list of topics.

Enable only the topics required for the intended use cases because each topic can affect:

Impact

Details

Event volume

Event volume

Salesforce entitlements

Salesforce entitlements

GermainUX ingestion

GermainUX ingestion

Storage requirements

Storage requirements

Privacy exposure

Privacy exposure

Alert volume

Alert volume

Typical categories include:

Category

Examples

API events

API events

Login and logout events

Login and logout events

Report events

Report events

File events

File events

Record events

Record events

Lightning events

Lightning events

Permission events

Permission events

Session-security events

Session-security events

Mobile events

Mobile events

The exact topic names depend on the Salesforce services and GermainUX version.

⛔ Disable an Event Topic

To stop collecting an individual topic while leaving the monitor active:

  1. Open GermainUX Workspace.

  2. Open the left navigation menu.

  3. Navigate to:

    System → Engine → Component Types

  4. Search for:

    Name = Salesforce Event Monitor
    
  5. Open the component type.

  6. Locate Topics.

  7. Remove the topic that should no longer be monitored.

  8. Save the configuration.

  9. Restart or refresh the applicable component if required.

  10. Confirm that events from the removed topic no longer arrive.

Record the previous topic list before editing it so the configuration can be restored if needed.

Editing the component type may affect every monitor using that type. Confirm the scope before removing a topic.

➕ Add or Restore an Event Topic

To add or restore a topic:

  1. Confirm that the Salesforce organization exposes the topic.

  2. Confirm that the integration user can subscribe to it.

  3. Open the Salesforce Event Monitor component type.

  4. Add the exact supported topic name to Topics.

  5. Save the configuration.

  6. Restart or refresh the component if required.

  7. Generate a controlled test event.

  8. Confirm that it appears in GermainUX.

Do not invent or approximate topic names. Use only event topics supported by both Salesforce and the installed GermainUX version.

⏹️ Disable Real-Time Event Monitoring

To stop all Salesforce real-time event collection:

  1. Open GermainUX Workspace.

  2. Open the left navigation menu.

  3. Select Germain.

  4. Open the State tab.

  5. Search for:

    Name = Salesforce Event Monitoring
    
  6. Locate the component associated with the intended Salesforce organization.

  7. Turn off the toggle in the Enabled column.

  8. Save the change if prompted.

Previously collected events remain available according to the configured retention policy.

🔁 Re-enable Monitoring

To resume all configured event subscriptions:

  1. Return to Germain → State.

  2. Search for Salesforce Event Monitoring.

  3. Turn on the Enabled toggle.

  4. Confirm that the OAuth connection is valid.

  5. Confirm the configured topic list.

  6. Save the configuration.

  7. Verify that new events arrive.

👀 View Real-Time Events

Open:

GermainUX Workspace → Dashboards → All → Salesforce RT Events

The dashboard can provide:

View

Details

Event volume

Event volume

Event trends

Event trends

API events

API events

Login and logout activity

Login and logout activity

Lightning record events

Lightning record events

Report execution and export events

Report execution and export events

Unknown Attachment

Record-change events

Record-change events

Unknown Attachment

Security-relevant activity

Security-relevant activity

Access to individual event details

Access to individual event details

Select an event or KPI to drill through to its attributes and related evidence.

Unknown Attachment


📊 Salesforce Real-Time Event KPIs

See Salesforce Real-Time Event KPIs.

Depending on the event type, useful measures include:

Measure

Details

Event count

Event count

Unique users

Unique users

Unique sessions

Unique sessions

Unique records

Unique records

Unique reports

Unique reports

Unique API clients

Unique API clients

Error count

Error count

Failure rate

Failure rate

Data volume

Data volume

Duration

Duration

Risk or severity

Risk or severity

Useful pivots may include:

Pivot

Details

Event type

Event type

User

User

Profile

Profile

Permission

Permission

IP address

IP address

Session

Session

API client

API client

Connected App

Connected App

Report

Report

Record

Record

Object

Object

Operation

Operation

Salesforce organization

Salesforce organization

Environment

Environment

Result or status

Result or status

🔔 Configure Alerts

Real-Time Event Monitoring is particularly valuable when events require immediate review.

🛡️ Security Alerts

Examples include:

Alert

Details

Successful login during a credential-stuffing attack

Successful login during a credential-stuffing attack

Suspected session hijacking

Suspected session hijacking

Sensitive-data access by an unauthorized user

Sensitive-data access by an unauthorized user

Unusual API behavior

Unusual API behavior

Unexpected Bulk API result download

Unexpected Bulk API result download

High-volume file download

High-volume file download

Administrator login as another user

Administrator login as another user

Unexpected permission assignment

Unexpected permission assignment

Report export containing sensitive data

Report export containing sensitive data

🔧 Operational Alerts

Examples include:

Alert

Details

Concurrent long-running Apex limit exceeded

Concurrent long-running Apex limit exceeded

Repeated API errors

Repeated API errors

Real-time event stream disconnected

Real-time event stream disconnected

No events received when activity is expected

No events received when activity is expected

Event volume deviates substantially from baseline

Event volume deviates substantially from baseline

A previously unseen event or error category appears

A previously unseen event or error category appears

Configure thresholds and categorization to avoid sending an alert for every routine event.

🔗 Correlate Events With Other Evidence

Real-Time Events become more useful when correlated with:

Evidence

Details

Salesforce user sessions

Salesforce user sessions

Session Replay

Session Replay

User clicks and navigation

User clicks and navigation

Apex exceptions

Apex exceptions

Debug Logs

Debug Logs

API and integration activity

API and integration activity

Audit changes

Audit changes

User-facing errors

User-facing errors

Business-process activity

Business-process activity

For example:

  1. A report-export event identifies a user exporting sensitive data.

  2. Browser monitoring identifies the Salesforce session.

  3. Session Replay shows the navigation and actions leading to the export.

  4. Audit data reveals a recent permission change.

  5. GermainUX alerts the security team with the related evidence.

Correlation depends on the identifiers available across the event sources.

✅ Validate Real-Time Event Monitoring

Test each required topic separately.

  1. Confirm that Salesforce Event Monitoring is enabled.

  2. Confirm that the Engine is connected to Salesforce.

  3. Verify the OAuth authorization and permissions.

  4. Review the configured topics.

  5. Generate a safe test event in a non-production environment.

  6. Open Salesforce RT Events.

  7. Confirm that the event appears.

  8. Verify its event type, user, timestamp, organization, and result.

  9. Test the applicable categorization.

  10. Confirm that any alert is triggered and routed correctly.

Use controlled tests that comply with organizational security policies. Do not simulate an actual credential attack or unauthorized access.

❌ No Real-Time Events Appear

If events are missing:

  1. Confirm that the Salesforce organization supports the event topic.

  2. Verify that the required Salesforce feature or license is active.

  3. Confirm that the integration user can subscribe to the topic.

  4. Verify the Salesforce OAuth connection.

  5. Check that Salesforce Event Monitoring is enabled.

  6. Confirm that the topic remains in the configured Topics list.

  7. Verify that the GermainUX Engine is running.

  8. Check Engine connectivity to Salesforce.

  9. Review Engine logs for authentication, subscription, network, and parsing errors.

  10. Confirm that a matching event occurred during the selected time range.

  11. Review dashboard organization, environment, and event-type filters.

  12. Check applicable Salesforce event-delivery entitlements and limits.

❓ Only Some Event Types Appear

If some topics work and others do not:

  • Verify Salesforce support and licensing for each missing topic.

  • Check permissions for the integration user.

  • Confirm the exact topic name.

  • Verify the topic is present in Topics.

  • Generate a known event of that type.

  • Review Engine logs for topic-specific subscription errors.

  • Confirm that the dashboard includes the corresponding KPI.

⏱️ Event Delivery Stops

If events appeared previously but stop arriving:

  1. Confirm that the Engine is running.

  2. Verify network connectivity.

  3. Check whether the OAuth token expired or was revoked.

  4. Confirm that the Connected App remains authorized.

  5. Review subscription and reconnection errors.

  6. Confirm that Salesforce still exposes the topic.

  7. Check Salesforce service status.

  8. Validate with a controlled test event.

  9. Restart the monitor if required.

Configure a health alert for interrupted or stale event streams when continuous collection is critical.

💾 Data Volume and Retention

Real-time event streams can generate substantial data.

Before enabling many topics:

  • Estimate expected event volume.

  • Enable only required topics.

  • Configure appropriate retention.

  • Monitor Salesforce delivery entitlements.

  • Monitor GermainUX ingestion and storage.

  • Categorize repetitive events.

  • Exclude non-actionable data.

  • Review high-volume topics after deployment.

🔒 Security and Privacy

Real-time events can contain sensitive security and activity information, including:

Sensitive Data

Details

User identities

User identities

IP addresses

IP addresses

Session identifiers

Session identifiers

Record and object identifiers

Record and object identifiers

Report names

Report names

File activity

File activity

API clients

API clients

Permission changes

Permission changes

Security-event details

Security-event details

Before production enablement:

  • Use a dedicated least-privilege integration account.

  • Restrict access to event dashboards and details.

  • Mask, anonymize, or exclude sensitive fields.

  • Never retain credentials, secrets, OAuth tokens, or reusable session identifiers.

  • Apply appropriate retention.

  • Review event use cases with Salesforce, security, privacy, and compliance owners.

ℹ️ Get More Information

GermainUX can help determine which monitoring, analytics and automation capabilities are appropriate for your Salesforce CRM environment.

Contact GermainUX Support.

Feature Availability: 2017.1 or later