# Salesforce EventLogFIle Object impossible to retreive

**URL:** <https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716>\
**Category:** Logstash\
**Created:** [May 15, 2017, 7:28am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716 "2017-05-15T07:28:50Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![saversano](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@saversano](https://discuss.elastic.co/u/saversano)\
**Post date:** [May 15, 2017, 7:28am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/1 "2017-05-15T07:28:50Z")

</div>

Hello Team,, i'm trying to retreive Logfiles from EventLogFile using Logstash and Salesforce plugin for logstash on my sandbox.  
I am able to retreive some objects (as per Opportunity, Account, Contact, etc.) but not EventLogFile.  
I'm administrator and i have all permissions.

Do anyone in this group has already implemented Logstash and Salesforce for Event Monitor files ?  
Here after is the logstash configuration i'm using. It works fine but if i replace Account with EventLogFile and Name with any field of EventLogFile it can't run with an error like [ERROR][logstash.agent] Cannot create pipeline {:reason=\>"Expected one of #, =\> at line 19, column 14 (byte 430)

Any Idea ?

Thanks in advance.

input {  
salesforce  
{  
client\_id =\> '\*\*\*\*\*\*\*\*\*\*2dCX6Q4hnHlQ35AQSYYL1Bx8h7KqXSCOn8ToRgbtvw6aVD2b0SURELIy5Js'  
client\_secret =\> '\*\*\*\*\*\*\*41977732'  
username =\> 'aaaa-bbbb@xxxx.demo'  
password =\> '\*\*\*\*\*\*\*\*!'  
security\_token =\> '\*\*\*\*\*\*\*\*\*7YaqScujdBq'  
sfdc\_fields =\> 'Name'  
sfdc\_object\_name =\> 'Account'  
use\_test\_sandbox =\> true  
}  
filter {  
}  
output {  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 15, 2017, 8:38am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/2 "2017-05-15T08:38:46Z")

</div>

The error message is telling you that LS found a syntax error in the config on line 19 column 14.

Please try the change again while making sure the quotes, fields =\> 'text' and braces are correctly balanced.

---

<div class="post-metadata">

**Author:** ![saversano](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@saversano](https://discuss.elastic.co/u/saversano)\
**Post date:** [May 15, 2017, 9:07am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/3 "2017-05-15T09:07:45Z")

</div>

Thank you for you response.  
The problem is that at line 19 of my configuration file there is this part **stdout { codec =\> rubydebug }**  
If you look at at the configuration file i post, this works fine. But if i use this particular Salesforce object (EventLogFile) it fails.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 15, 2017, 9:24am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/4 "2017-05-15T09:24:17Z")

</div>

The syntax parser will report that line because that is where it ran out of possibilities.

Its a bit like if you are trekking through the jungle and come to a river but no bridge - you would have to say "i'm expecting a bridge" you would not be able to say "I should have taken the right fork 2 km ago" (well you might because you have a map, memory and imagination 🙂 )

Check the earlier part of the config.

---

<div class="post-metadata">

**Author:** ![saversano](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@saversano](https://discuss.elastic.co/u/saversano)\
**Post date:** [May 15, 2017, 9:28am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/5 "2017-05-15T09:28:14Z")

</div>

there will be a particular configuration for this particular salesforce object but i don't know which parameter in configuration file i have to adapt. thanks for your support

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 15, 2017, 10:19am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/6 "2017-05-15T10:19:48Z")

</div>

After you have solved the config syntax error then you may get errors from the salesforce input plugin and those error lines in the LS logs will read `[<timestamp>][ERROR][logstash.inputs.salesforce] ....`  
Are you getting any Errors or Warnings with this log pattern?

---

<div class="post-metadata">

**Author:** ![saversano](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@saversano](https://discuss.elastic.co/u/saversano)\
**Post date:** [May 15, 2017, 12:09pm UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/7 "2017-05-15T12:09:10Z")

</div>

[2017-05-15T13:59:55,469][ERROR][logstash.pipeline] Error registering plugin {:plugin=\>"\<LogStash::Inputs::Salesforce client\_id=\>"\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*X6Q4hnHlQ35AQSYYL1Bx8h7KqXSCOn8ToRgbtvw6aVD2b0SURELIy5Js", client\_secret=\>"xxxxxxxx1977732", username=\>"xxxxxxxxxxx@.demo.fr", password=\>"xxxxxxxx", security\_token=\>"xxxxxxxxxDM7YaqScujdBq", sfdc\_object\_name=\>"EventLogFile", use\_test\_sandbox=\>true, id=\>"e494f5b7d04b25bb4e4179ffb69b5550d989d55f-1", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_ad3c0d4d-17a7-40db-b714-d12ff4ff30be", enable\_metric=\>true, charset=\>"UTF-8"\>, to\_underscores=\>false\>", :error=\>"NOT\_FOUND: The requested resource does not exist"}  
[2017-05-15T13:59:55,529][ERROR][logstash.agent] Pipeline aborted due to error {:exception=\>#Faraday::ResourceNotFound

This is what i see when i execute bin/logstash -f logstash.conf.  
I Know for sure that the EventLogFile object exists because i can see it in Salesforce.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 15, 2017, 1:10pm UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/8 "2017-05-15T13:10:00Z")

</div>

The above error you get now comes from the plugin registration period of the pipeline startup. It tries to "describe" the object referred to by `sfdc_object_name`

Please check that you have permissions. [https://developer.salesforce.com/docs/atlas.en-us.206.0.object\_reference.meta/object\_reference/sforce\_api\_objects\_eventlogfile.htm](https://developer.salesforce.com/docs/atlas.en-us.206.0.object_reference.meta/object_reference/sforce_api_objects_eventlogfile.htm)

You should be able to use `curl` see examples:

> **[Working with Object Metadata | Force.com REST API Developer Guide | Salesforce...](https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/using_resources_working_with_object_metadata.htm)**
>
> Build versatile and lightweight solutions that integrate your Salesforce data using REST API. This simple RESTful interface is powerful, convenient, and great for writing mobile and web apps.

  

> **[Using cURL in the REST Examples | Force.com REST API Developer Guide |...](https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/intro_curl.htm)**
>
> Build versatile and lightweight solutions that integrate your Salesforce data using REST API. This simple RESTful interface is powerful, convenient, and great for writing mobile and web apps.

  

> **[Understanding Authentication | Force.com REST API Developer Guide | Salesforce...](https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/intro_understanding_authentication.htm)**
>
> Build versatile and lightweight solutions that integrate your Salesforce data using REST API. This simple RESTful interface is powerful, convenient, and great for writing mobile and web apps.

---

<div class="post-metadata">

**Author:** ![saversano](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@saversano](https://discuss.elastic.co/u/saversano)\
**Post date:** [May 15, 2017, 3:14pm UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/9 "2017-05-15T15:14:11Z")

</div>

Thank you for the link  
If i use curl for retreiving Eventlogfile from everything is all right. I already do that.  
This error appears only when i use EventLogFile object with Logstash.  
My configuration Logstash is ok because if i replace EventLogFile object with Account (or Case, or Opportunity or whatever else) it run

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 17, 2017, 9:05am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/10 "2017-05-17T09:05:47Z")

</div>

Please post your curl request & response (redacted as necessary)

---

<div class="post-metadata">

**Author:** ![saversano](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@saversano](https://discuss.elastic.co/u/saversano)\
**Post date:** [May 17, 2017, 5:38pm UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/11 "2017-05-17T17:38:58Z")

</div>

Some security parameters has been hiden.

This is the first request for gathering the access tocken

curl [https://cs88.salesforce.com/services/oauth2/token](https://cs88.salesforce.com/services/oauth2/token) -d "grant\_type=password" -d "client\_id=xxxxxxxxxxxxxxxxxxxxx2dCX6Q4hnHlQ35AQSYYL1Bx8h7KqXSCOn8ToRgbtvw6aVD2b0SURELIy5Js" -d "client\_secret=xxxxxxxxxxxx32" -d "username=xxxxxxxxxsano@aaaaaa.demo" -d "password=xxxxxx" -H "X-PrettyPrint:1" | jq -r '.access\_token'`

REPONSE

{  
"access\_token" : "00D9E000000CzEZ!ARAAQLq5c8VsCrPxhgbivTabRx9iRj\_BNr9bC6.b3ONM2E\_QZiPoaIeXlRxh79g5XgxFmpk0ivqphiQ2o8fB2U3szO8ZeTle",  
"instance\_url" : "[https://xxxxx.cs88.my.salesforce.com](https://xxxxx.cs88.my.salesforce.com)",  
"id" : "[https://test.salesforce.com/id/00D9E000000CzEZUA0/0050Y000000jo3wQAA](https://test.salesforce.com/id/00D9E000000CzEZUA0/0050Y000000jo3wQAA)",  
"token\_type" : "Bearer",  
"issued\_at" : "1495038352781",  
"signature" : "eihA8CnuustruRDzW+vSj06cxhfPSWNChVmVxBvDUkY="  
}

Then this request  
elfs=`curl https://${instance}.salesforce.com/services/data/v32.0/query?q=Select+Id+,+EventType+,+LogDate+From+EventLogFile+Where+LogDate+=+${day} -H "Authorization: Bearer ${access\_token}" -H "X-PrettyPrint:1"

RESPONSE

{  
"totalSize" : 4,  
"done" : true,  
"records" : [ {  
"attributes" : {  
"type" : "EventLogFile",  
"url" : "/services/data/v32.0/sobjects/EventLogFile/0AT9E000000DWjkWAG"  
},  
"Id" : "0AT9E000000DWjkWAG",  
"EventType" : "Login",  
"LogDate" : "2017-05-15T00:00:00.000+0000"  
}, {  
"attributes" : {  
"type" : "EventLogFile",  
"url" : "/services/data/v32.0/sobjects/EventLogFile/0AT9E000000DXQDWA4"  
},  
"Id" : "0AT9E000000DXQDWA4",  
"EventType" : "Login",  
"LogDate" : "2017-05-16T00:00:00.000+0000"  
}, {  
"attributes" : {  
"type" : "EventLogFile",  
"url" : "/services/data/v32.0/sobjects/EventLogFile/0AT9E000000DWjlWAG"  
},  
"Id" : "0AT9E000000DWjlWAG",  
"EventType" : "Logout",  
"LogDate" : "2017-05-15T00:00:00.000+0000"  
}, {  
"attributes" : {  
"type" : "EventLogFile",  
"url" : "/services/data/v32.0/sobjects/EventLogFile/0AT9E000000DXQEWA4"  
},  
"Id" : "0AT9E000000DXQEWA4",  
"EventType" : "Logout",  
"LogDate" : "2017-05-16T00:00:00.000+0000"  
}

The this

curl --compressed "https://${instance}.salesforce.com/services/data/v32.0/sobjects/EventLogFile/${ids[$i]}/LogFile" -H "Authorization: Bearer ${access\_token}" -H "X-PrettyPrint:1" -o "${logDates[$i]}/${eventTypes[$i]}-${logDates[$i]}.csv"

With this i can extract Log files from Salesforce

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 18, 2017, 6:36pm UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/12 "2017-05-18T18:36:38Z")

</div>

So LS has a problem with `describe` `EventLogFile`.  
Can you post the curl of the describe API call? I see you did the query but LS has not got to that as yet.

---

<div class="post-metadata">

**Author:** ![saversano](https://avatars.discourse-cdn.com/v4/letter/s/8e7dd6/32.png) [@saversano](https://discuss.elastic.co/u/saversano)\
**Post date:** [May 29, 2017, 4:09pm UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/13 "2017-05-29T16:09:32Z")

</div>

Hi @guyboertje, sorry for late. I haven't the curl request of the describe API call. i don't know where find it.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 30, 2017, 8:35am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/14 "2017-05-30T08:35:30Z")

</div>

From this page...  
[`https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/resources_sobject_describe.htm`](https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/resources_sobject_describe.htm)

Something like:

`curl https://${instance}.salesforce.com/services/data/v32.0/sobjects/EventLogFile/describe/ -H "Authorization: Bearer ${access_token}" -H "X-PrettyPrint:1"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 8:35am UTC](https://discuss.elastic.co/t/salesforce-eventlogfile-object-impossible-to-retreive/85716/15 "2017-06-27T08:35:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
