Salesforce Service Cloud logs into Microsoft Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-3330772%22%20slang%3D%22en-US%22%3ESalesforce%20Service%20Cloud%20logs%20into%20Microsoft%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3330772%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ehas%20anyone%20managed%20to%20successfully%20ingest%20SF%20logs%20into%20Microsoft%20Sentinel%20using%20the%20data%20connector.%20The%20connector%20uses%20Azure%20functions%20to%20connect%20to%20the%20SF%20lightening%20platform%20REST%20API%20to%20pull%20data%20into%20Sentinel.%20The%20function%20app%20for%20SF%20shows%20connected%20but%20we%20are%20getting%20the%20following%20error%20looking%20at%20the%20Function%20%26gt%3B%20Monitor%20%26gt%3B%20Invocations%20%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EResult%3A%20Failure%20Exception%3A%20TypeError%3A%20'NoneType'%20object%20is%20not%20iterable%20Stack%3A%20File%20%22%2Fazure-functions-host%2Fworkers%2Fpython%2F3.6%2FLINUX%2FX64%2Fazure_functions_worker%2Fdispatcher.py%22%2C%20line%20405%2C%20in%20_handle__invocation_request%20invocation_id%2C%20fi_context%2C%20fi.func%2C%20args)%20File%20%22%2Fusr%2Flocal%2Flib%2Fpython3.6%2Fconcurrent%2Ffutures%2Fthread.py%22%2C%20line%2056%2C%20in%20run%20result%20%3D%20self.fn(*self.args%2C%20**self.kwargs)%20File%20%22%2Fazure-functions-host%2Fworkers%2Fpython%2F3.6%2FLINUX%2FX64%2Fazure_functions_worker%2Fdispatcher.py%22%2C%20line%20612%2C%20in%20_run_sync_func%20func)(params)%20File%20%22%2Fazure-functions-host%2Fworkers%2Fpython%2F3.6%2FLINUX%2FX64%2Fazure_functions_worker%2Fextension.py%22%2C%20line%20215%2C%20in%20_raw_invocation_wrapper%20result%20%3D%20function(**args)%20File%20%22%2Fhome%2Fsite%2Fwwwroot%2FSalesforceSentinelConnector%2F__init__.py%22%2C%20line%20216%2C%20in%20main%20for%20line%20in%20pull_log_files()%3A%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3Eany%20ideas%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3330772%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESIEM%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Contributor

Hi,

 

has anyone managed to successfully ingest SF logs into Microsoft Sentinel using the data connector. The connector uses Azure functions to connect to the SF lightening platform REST API to pull data into Sentinel. The function app for SF shows connected but we are getting the following error looking at the Function > Monitor > Invocations :

 

Result: Failure Exception: TypeError: 'NoneType' object is not iterable Stack: File "/azure-functions-host/workers/python/3.6/LINUX/X64/azure_functions_worker/dispatcher.py", line 405, in _handle__invocation_request invocation_id, fi_context, fi.func, args) File "/usr/local/lib/python3.6/concurrent/futures/thread.py", line 56, in run result = self.fn(*self.args, **self.kwargs) File "/azure-functions-host/workers/python/3.6/LINUX/X64/azure_functions_worker/dispatcher.py", line 612, in _run_sync_func func)(params) File "/azure-functions-host/workers/python/3.6/LINUX/X64/azure_functions_worker/extension.py", line 215, in _raw_invocation_wrapper result = function(**args) File "/home/site/wwwroot/SalesforceSentinelConnector/__init__.py", line 216, in main for line in pull_log_files():

 

any ideas?

 

Thanks

0 Replies