Integration: Kaseya SIEM and Salesforce
Kaseya SIEM
NAVIGATION Organizations > Edit Organization (pencil icon) > + New Application > Salesforce
PERMISSIONS Permission to manage organizations and applications in Kaseya SIEM. Organization configured in Kaseya SIEM.
Salesforce
NAVIGATION Setup > Domain Management > My Domain
PERMISSIONS A Salesforce System Administrator account is required to complete the authentication and authorization process for the integration.
The Kaseya SIEM and Salesforce integration imports Salesforce user activity and security events into Kaseya SIEM, enabling the platform to monitor user behavior, authentication activity, and security-related events across the Salesforce environment.
Prerequisites
This integration requires:
-
A Salesforce tenant
-
The Salesforce service domain
-
A Salesforce System Administrator account
-
Permission to authorize third-party applications in Salesforce
Salesforce environments may use one of the following security licensing tiers:
-
Basic Security
-
Salesforce Event Monitoring
-
Salesforce Shield
How to...
Before configuring the integration, identify the Salesforce service domain:
-
Log in to Salesforce.
-
Click Setup.
-
From the side navigation menu, expand Domain Management.
-
Click My Domain.
-
Copy only the domain value.
EXAMPLE mydomain.mysalesforce.com
EXAMPLE Incorrect domain entry that includes URL prefix: www.mydomain.my.salesforce.com or https://mydomain.my.salesforce.com Domains entered in this format will not work.
NOTE Domains containing lightning may not connect successfully. Use the standard my.salesforce.com domain whenever available.
Steps in Kaseya SIEM
-
In Kaseya SIEM, navigate to Organizations.
-
Click Edit Organization (pencil icon).
-
Click +New Application.
-
Select Salesforce.
-
Enter the Salesforce service domain you copied in Locate the Salesforce service domain.
-
Click Connect.
Steps in Salesforce
-
When redirected to Salesforce, sign in using a Salesforce System Administrator account.
-
Complete any required multi-factor authentication or identity verification steps.
-
Review the requested permissions and click Allow.
Results
-
Salesforce appears as an application associated with the organization.
-
Salesforce user accounts are imported into Kaseya SIEM.
-
Salesforce user activity and security events become available for monitoring and alerting.
NOTE Kaseya SIEM imports Salesforce user accounts. It does not import Salesforce business objects, records, or organizational data.
To disconnect the integration:
-
Navigate to the organization in Kaseya SIEM.
-
Open the Salesforce application configuration.
-
Select Disconnect or remove the application.
-
Confirm the action.
Results
-
Salesforce activity is no longer imported into Kaseya SIEM.
-
Existing Salesforce users, permissions, and tenant configurations remain unchanged.
-
The integration can be reconnected later if needed.
FAQ
Salesforce reports login events and new device events from different endpoints. Beyond the user ID, the events do not contain enough information to always correlate them. Salesforce also evaluates browser cookie information when determining whether a login originates from a previously seen device. If that cookie changes, Salesforce may generate a new device event even when the user is signing in from the same physical device.
This behavior is determined by Salesforce and is not a Kaseya SIEM interpretation of the data. For more information, see Salesforce documentation regarding Client Browser behavior.
No. Kaseya SIEM imports Salesforce user accounts and security-related activity. It does not import Salesforce organizations, business records, opportunities, contacts, or other CRM data.