# Filebeat Input for salesforce

**URL:** <https://discuss.elastic.co/t/filebeat-input-for-salesforce/365621>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 27, 2024, 1:56pm UTC](https://discuss.elastic.co/t/filebeat-input-for-salesforce/365621 "2024-08-27T13:56:41Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![kkalwaysok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kkalwaysok/32/123733_2.png) [@kkalwaysok](https://discuss.elastic.co/u/kkalwaysok)\
**Post date:** [August 27, 2024, 1:56pm UTC](https://discuss.elastic.co/t/filebeat-input-for-salesforce/365621/1 "2024-08-27T13:56:41Z")

</div>

Hello,

I'm trying to configure multiple salesforce objects using filebeat inputs and below is the example config. When I verified the logs I can see the query running but I can't see the data. Any help with how to configure multiple modules in salesforce is much appreciated.

Config:

- type: salesforce  
id: my-generic-id  
fields:  
environment: 'generic-sit'  
enabled: true  
version: 56  
auth.oauth2:  
user\_password\_flow:  
enabled: true  
client.id: ################  
client.secret: ##########  
token\_url: ###########.salesforce.com  
username: #############  
password: ###################  
jwt\_bearer\_flow:  
enabled: false  
client.id: client-id  
client.username: salesforce-instance@user.in  
client.key\_path: server\_client.key  
url: [https://login.salesforce.com](https://login.salesforce.com)  
url: #############.salesforce.com  
event\_monitoring\_method:  
event\_log\_file:  
enabled: false  
interval: 1h  
query:  
default: "SELECT Id,CreatedDate,LogDate,LogFile FROM EventLogFile WHERE EventType = 'Login' ORDER BY CreatedDate ASC NULLS FIRST"  
value: "SELECT Id,CreatedDate,LogDate,LogFile FROM EventLogFile WHERE EventType = 'Login' AND CreatedDate \> [[.cursor.event\_log\_file.last\_event\_time]] ORDER BY CreatedDate ASC NULLS FIRST"  
cursor:  
field: "CreatedDate"  
object:  
enabled: true  
interval: 5m  
query:  
default: "SELECT Id,Integration\_Utility\_\_c,Holistic\_Application\_\_c,Work\_Hours\_\_c,Severity\_\_c,Session\_Identifier\_\_c,Name,Class\_Method\_\_c,Class\_Name\_\_c,Component\_Method\_\_c,Component\_Name\_\_c,Error\_Log\_Time\_\_c,Error\_Message\_\_c,Device\_\_c,Browser\_\_c,Integration\_Log\_Type\_\_c,Document\_Detail\_\_c,End\_Point\_URL\_\_c,Integration\_Name\_\_c,Integration\_Type\_\_c,Additional\_Error\_Information\_\_c,Requested\_On\_\_c,Request\_Id\_\_c,Stack\_Trace\_\_c,User\_Info\_\_c,User\_Profile\_\_c,CreatedDate,CreatedById,HTTP\_Status\_Code\_\_c,Record\_Id\_\_c,RequestJSON\_\_c,Responded\_On\_\_c,ResponseJSON\_\_c,FederationId\_\_c,LastModifiedDate,LastModifiedById FROM Generic\_Log\_\_c"  
value: "SELECT Id,Integration\_Utility\_\_c,Holistic\_Application\_\_c,Work\_Hours\_\_c,Severity\_\_c,Session\_Identifier\_\_c,Name,Class\_Method\_\_c,Class\_Name\_\_c,Component\_Method\_\_c,Component\_Name\_\_c,Error\_Log\_Time\_\_c,Error\_Message\_\_c,Device\_\_c,Browser\_\_c,Integration\_Log\_Type\_\_c,Document\_Detail\_\_c,End\_Point\_URL\_\_c,Integration\_Name\_\_c,Integration\_Type\_\_c,Additional\_Error\_Information\_\_c,Requested\_On\_\_c,Request\_Id\_\_c,Stack\_Trace\_\_c,User\_Info\_\_c,User\_Profile\_\_c,CreatedDate,CreatedById,HTTP\_Status\_Code\_\_c,Record\_Id\_\_c,RequestJSON\_\_c,Responded\_On\_\_c,ResponseJSON\_\_c,FederationId\_\_c,LastModifiedDate,LastModifiedById FROM Generic\_Log\_\_c WHERE CreatedDate \> [[.cursor.object.first\_event\_time]]"  
cursor:  
field: "CreatedDate"
- type: salesforce  
id: my-login-id  
fields:  
test: 'api-sit'  
enabled: true  
version: 56  
auth.oauth2:  
user\_password\_flow:  
enabled: true  
client.id: ##########  
client.secret: ################  
token\_url: #############.salesforce.com  
username: ##################  
password: #################  
jwt\_bearer\_flow:  
enabled: false  
client.id: client-id  
client.username: salesforce-instance@user.in  
client.key\_path: server\_client.key  
url: [https://login.salesforce.com](https://login.salesforce.com)  
url: ###############.salesforce.com  
event\_monitoring\_method:  
event\_log\_file:  
enabled: false  
interval: 1h  
object:  
enabled: true  
interval: 1h  
query:  
default: "SELECT FIELDS(STANDARD) FROM LoginEvent"  
value: "SELECT FIELDS(STANDARD) FROM LoginEvent WHERE EventDate \> [[.cursor.object.first\_event\_time]]"  
cursor:  
field: "EventDate"

Thanks,  
KK
