Mar 05 2019 01:52 PM
Mar 06 2019 02:50 AM
What we actually have done is the following:
integrated Salesforce with CloudApp security portal, that collects and correlate SF logs,
integrated CloudApp security with Sentinel. Coz, SF has rate limiting, and CloudApp security integration takes care of that. This flow somehow solved Salesforce part.
However, AWS is a different story, you have options for different SaaS logs to analyze, you might need to connect it to Sentinel directly (VPC logs, KMS logs, etc).