Configure Salesforce for Arctic Wolf monitoring
You can configure Salesforce® to send the necessary logs to Arctic Wolf® for security monitoring.
Arctic Wolf only supports Salesforce monitoring when SSO and MFA are enabled at the organization level for Salesforce sign-ins.
If you have the Group Edition of Salesforce or enable SSO and MFA enforcement at the permission set or profile levels, Arctic Wolf cannot monitor the integration. For example, these enforcement methods are not supported:
- MFA enforced through the Multi-Factor Authentication for API Logins permission.
- MFA enforced by setting the Session Security Level Required at Login for a profile to High Assurance.
- SSO enforced through the Is Single Sign-On Enabled permission.
For more information about these features, see Salesforce MFA FAQ.
Salesforce limits the number of API calls that all users and applications sharing a Salesforce tenant can perform in a 24-hour period. If this API request limit is exceeded, new API calls are denied until the number of API calls in the last 24 hours falls below the limit. The Arctic Wolf Sensor typically makes fewer than 250 API calls each hour or 6,000 each day. Sometimes, the number of API calls is higher than this average, but it should never exceed 10,000 API calls each day.
These resources are required:
- System administrator permissions for the Salesforce organization that you want Arctic Wolf to monitor.
- A Salesforce Sales Cloud license.
- Integration API access. If your organization uses the Professional Edition of Salesforce, you can purchase the required API access from Salesforce for an additional fee. Contact your Salesforce account executive to enable this functionality.
Note:
The required integration APIs are enabled automatically in the Enterprise, Unlimited, and Performance editions of Salesforce.
These actions are required:
-
Verify with your Salesforce administrator that Arctic Wolf API usage rates will not exceed your API request limit for your organization.
For more information about Salesforce API request limits, see API Request Limits and Allocations.
Create or select a Salesforce profile
You can either create a Salesforce profile or select an existing profile.
Arctic Wolf strongly recommends that you create a new Salesforce profile and user for log collection and forwarding to the Arctic Wolf Sensor. Having a dedicated user limits the permissions that the Arctic Wolf Sensor requires and allows for better visibility over Arctic Wolf Sensor activities.
Create a Salesforce profile
Select a Salesforce profile
Create a new user for log collection
Arctic Wolf strongly recommends that you create a new Salesforce profile and user for log collection and forwarding to the Arctic Wolf Sensor. Having a dedicated user limits access to the permissions that the Arctic Wolf Sensor requires and allows for better visibility over Arctic Wolf Sensor activities.
If you want to create a new user for log collection:
Create a security token for the user
Make sure that no other services use the existing security token for an existing user because creating a new security token invalidates previous tokens.
If you created a new user or profile or you do not have access to the existing security token for the existing user, create a new security token: