Learn more about the Salesforce data source wizard in Cortex XSIAM.
Cortex XSIAM provides three primary methods for connecting to your Salesforce instance. Your choice depends on whether you need to ingest security event logs for monitoring, use the guided wizard setup for integrated services, or deploy specific legacy content packs for niche workflows.
Cortex XSIAM can ingest identity metadata, login history, audit trails, and security monitoring events from Salesforce via integrations to help you secure user identities, monitor for real-time threats, and automate issue response. To simplify integration setup, a new Salesforce wizard allows you to select specific capabilities based on your operational needs. The wizard then automatically identifies and provisions the underlying integrations required to support these capabilities.
The following table outlines the capabilities currently available in the wizard and the integrations it uses for each.
Capability | Functionality | Use Cases | Underlying Integrations Used |
|---|---|---|---|
Automation and Remediation | Execute automations and commands across Salesforce and its Identity Access Management (IAM) services. |
|
|
Security Posture | Detect, monitor, and alert on your cloud application settings. |
| N/A |
Prerequisite
RBAC permissions: Requires View/Edit permissions for Log Collections, Data Sources, and Integrations (under Configurations & Data Collections).
Content packs: Ensure the Salesforce and Base content packs are installed or updated to the latest version.
Gateway permissions: Requires Account Admin or Instance Administrator permissions for configuring egress settings in the Cortex Gateway to allow communication with your Salesforce Domain URL.
Salesforce requirements depend on the capabilities you use: