Loading
Prepare for Email to Become the Default Login ExperienceRead More
Set Up and Maintain Your Salesforce Organization
View Events and Provide Feedback

View Events and Provide Feedback

View recent or all Threat Detection events using the Threat Detection app in the Salesforce UI. The displayed events are stored in their corresponding storage objects: ReportAnomalyEventStore, SessionHijackingEventStore, and CredentialStuffingEventStore. Associate a feedback object with a particular event to record the severity of the threat, such as Malicious or Not a Threat.

Required Editions

Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.

Available in: Enterprise, Unlimited, and Developer Editions

Requires Salesforce Shield or Salesforce Event Monitoring add-on subscriptions.

User Permissions Needed  
To view the Threat Detection events: View Threat Detection Events

By default, the Threat Detection app isn’t visible in Salesforce. If necessary, make it visible as described in Make the Threat Detection App Visible to Users.

  1. From App Launcher, click Threat Detection.
    App Launcher with Threat Detection app highlighted.
  2. Click the tabs for list views of recent or all events stored in the GuestUserAnomalyEventStore, ReportAnomalyEventStore, SessionHijackingEventStore, ApiAnomalyEventStore, or CredentialStuffingEventStore objects.
  3. To view an event’s details, click its link. Information such as the date the event occurred, its score, and a summary of the event is displayed.
    Each type of event displays other details appropriate to the type of detected threat. For example, the Session Hijacking Event Store tab displays previous and current browser fingerprint information. The Report Anomaly Event Store tab displays the report ID associated with the detected threat.
    Click Related to view the associated feedback, if any.
  4. Click Provide Feedback to specify whether a specific detected threat is Malicious, Suspicious, Not a Threat, or Unknown.
    You can associate only one feedback object with each event. If you try to provide more than one feedback object, you get an error. If the severity of a threat changes after you provided feedback, edit the response.
    Guest User Anomaly Event details page with Provide Feedback button highlighted
 
Loading
Salesforce Help | Article