Our GSOC (Global Security Operations Center) is now monitoring Salesforce logs.
For some logs the volume is huge, so we add filters in our SIEM's collect server to filter on the "PolicyID" of Event Monitoring / Transaction Security Policies.
However for the "API Event" big object the PolicyID is always empty leaving us no possibility to filter on that.
Anyone has already encountered the same issue? how did you proceed? would there be a way to filter this directly from the Salesforce API?
Thank you very much beforehand.
Hey guys, thank you very much for both of your answers!!
@Himanshu Shekharactually we already implemented Transaction Security Policy via the TSP accelerator package. However, when we connected our SIEM to Salesforce, our Professional Services told us that the only way to retrieve the Transaction Security Policies events was to take all the Salesforce event logs and then to filter on the PolicyID.
But if I understood properly your answer... you are mentioning a way to take directly into our SIEM Splunk only the TSP alerts. Do you have a link to the resource explaining how we can implement this process?
Thank you very much beforehand