Months after installing the Splunk App for Salesforce, the LoginHistory input stopped pulling data. I tried disabling the current input and recreating one from scratch, but nothing is being indexed. Not seeing any ExecProcessor errors.
Customer double checked their SFDC user permissions, and nothing has changed since implementation.
What's the correct approach to troubleshooting this?
↧