Newer Version Available

This content describes an older version of this product. View Latest

Insecure External Assets Event Type

Insecure External Assets events contain information about external assets, such as images or videos, accessed by users over an insecure HTTP protocol. The event lists all your Salesforce pages that contain insecure assets hosted on third-party sites that your users loaded with a Chrome, Firefox, Microsoft Edge, or Safari browser. This event type is available in the EventLogFile object in API version 42.0 and later.

Assets over HTTP can be manipulated through man-in-the-middle and other types of attacks. The attacks can trick users into sending their Salesforce credentials to malicious sites. We recommend that you use HTTPS in your custom code and templates for any asset you’re loading from external sites.

For details about event monitoring, see the Trailhead Event Monitoring module or the REST API Developer’s Guide.

Fields

Field Details
ASSET_TYPE
Type
String
Description
Type of insecure asset.
Possible Values
  • Base URI
  • Connect
  • Font
  • Frame Ancestor: External page that embeds the Salesforce page in an iframe
  • Frame
  • Image
  • Media
  • Object
  • Other
  • Plugin Types
  • Script
  • Style
CLIENT_IP
Type
String
Description
The IP address of the client that’s using Salesforce services. A Salesforce internal IP (such as a login from Salesforce Workbench or AppExchange) is shown as “Salesforce.com IP”.
Example
96.43.144.26
CPU_TIME
Type
Number
Description
The CPU time in milliseconds used to complete the request. This field indicates the amount of activity taking place in the app server layer, highlighting pieces of Apex or Visualforce code that need refactoring.
DOCUMENT_URI
Type
String
Description
URL of the page that contains the insecure asset, excluding the query parameter.
Example
https://company.my.salesforce.com/00XXXXXXXXX
EVENT_TYPE
Type
String
Description
The type of event.
Example
ReportExport, URI, API, RestApi, and so on. For details, see EventLogFile Supported Event Types.
INSECURE_URI
Type
String
Description
Insecure external asset URL.
Example
http://pbs.twimg.com/profile_images/5699091412070816/Z4Stwts_normal.jpeg
LOGIN_KEY
Type
String
Description
The string that ties together all events in a given user’s login session. It starts with a login event and ends with either a logout event or the user session expiring.
Example
GeJCsym5eyvtEK2I
ORGANIZATION_ID
Type
String
Description
The 15-character ID of the org.
Example
00D000000000123
REQUEST_ID
Type
String
Description
The unique ID of a single transaction. A transaction can contain one or more events. Each event in a given transaction has the same REQUEST_ID.
Example
3nWgxWbDKWWDIk0FKfF5DV
RUN_TIME
Type
Number
Description
The amount of time that the request took in milliseconds.
SESSION_KEY
Type
String
Description
The user’s unique session ID. You can use this value to identify all user events within a session. When a user logs out and logs in again, a new session is started.
Example
d7DEq/ANa7nNZZVD
TIMESTAMP
Type
String
Description
The access time of Salesforce services.
Example
20130715233322.670
TIMESTAMP_DERIVED
Type
DateTime
Description
The access time of Salesforce services in ISO8601-compatible format (YYYY-MM-DDTHH:MM:SS.sssZ)
Example
2015-07-27T11:32:59.555Z
TYPE
Type
String
Description
Type of Salesforce page.
Possible Values
  • Appserver: Page without My Domain subdomain (for example, https://na44.salesforce.com)
  • Communities: Customer community
  • Email: Email preview
  • Login: Login page (for example, https://login.salesforce.com)
  • Mydomain: Page on My Domain subdomain (for example, https://mycompany.my.salesforce.com)
  • Sites: Customer site
  • Static: Static content (for example, https://sfdcstatic.com)
  • Unknown: other type of page
URI
Type
String
Description
The URI of the page that’s receiving the request.
Example
/home/home.jsp
URI_ID_DERIVED
Type
ID
Description
The 18-character case insensitive ID of the URI of the page that’s receiving the request.
USER_ID
Type
Id
Description
The 15-character ID of the user who’s using Salesforce services through the UI or the API.
Example
00530000009M943
USER_ID_DERIVED
Type
Id
Description
The 18-character case insensitive ID of the user who’s using Salesforce services through the UI or the API.
Example
00590000000I1SNIA0