Newer Version Available

This content describes an older version of this product. View Latest

Insecure External Assets Event Type

Insecure External Assets events contain information about external assets. External assets include images or videos accessed by users over an insecure HTTP protocol. The event lists all your Salesforce pages that contain assets hosted insecurely on third-party sites that users loaded with a Chrome, Firefox, Microsoft Edge, or Safari browser. The INSECURE_URI field contains the URI being used to load the asset insecurely. The Insecure External Assets event type is available in the EventLogFile object in API version 42.0 and later.

Assets over HTTP can be manipulated through man-in-the-middle and other types of attacks. These attacks can trick users into sending their Salesforce credentials to malicious sites. Always use HTTPS in your custom code and templates for any asset you’re loading from external sites.

Because HTTPS connections are required to load external assets, Insecure External Assets events no longer apply. In Spring ’25 and later, this event type captures no data.

To view blocked redirections and content security policy (CSP) violations for your org, use the BrowserPolicyViolation object.

Important

For details about event monitoring, see the Trailhead Event Monitoring module or the REST API Developer’s Guide.

Fields

Field Details
ASSET_TYPE
Type
String
Description
Type of insecure asset.
Possible Values
  • Base URI
  • Connect
  • Font
  • Frame Ancestor: External page that embeds the Salesforce page in an iframe
  • Frame
  • Image
  • Media
  • Object
  • Other
  • Plugin Types
  • Script
  • Style
CLIENT_IP
Type
String
Description
The IP address of the client that’s using Salesforce services. A Salesforce internal IP (such as a login from AppExchange) is shown as “Salesforce.com IP”.
For example: 96.43.144.26.
CPU_TIME
Type
Number
Description
The CPU time in milliseconds used to complete the request. This field indicates the amount of activity taking place in the app server layer.
DISPOSITION
Type
String
Description
If the insecure external asset is related to your content security policy (CSP), the HTTP header that identified the insecure asset.
Available in API version 61.0 and later.
Possible Values
  • enforce—The Content-Security-Policy header identified the insecure external asset.
  • report—The Content-Security-Policy-Report-Only header identified the insecure external asset.
DOCUMENT_URI
Type
String
Description
URL of the page that contains the insecure asset, excluding the query parameter.
Example
https://company.my.salesforce.com/00XXXXXXXXX
EVENT_TYPE
Type
String
Description
The type of event. The value is always InsecureExternalAssets.
INSECURE_URI
Type
String
Description
Insecure external asset URL being used to load an asset insecurely. For example, loading Javascript libraries using http://ajax.googleapis.com/  in your custom code logs an Insecure External Asset Event with the INSECURE_URI  field set to this URL. Find this reference in your code and update it to use https://ajax.googleapis.com/  instead.
Example
http://pbs.twimg.com/profile_images/5699091412070816/Z4Stwts_normal.jpeg
LOGIN_KEY
Type
String
Description
The string that ties together all events in a given user’s login session. It starts with a login event and ends with either a logout event or the user session expiring.
For example: GeJCsym5eyvtEK2I.
NETWORK_ID
Type
String
Description
The ID of the Experience Cloud site related to the request, if applicable.
Available in API version 61.0 and later.
ORGANIZATION_ID
Type
String
Description
The 15-character ID of the org.
Example
00D000000000123
REQUEST_ID
Type
String
Description
The unique ID of a single transaction. A transaction can contain one or more events. Each event in a given transaction has the same REQUEST_ID.
For example: 3nWgxWbDKWWDIk0FKfF5DV.
RUN_TIME
Type
Number
Description
The amount of time that the request took in milliseconds.
SESSION_KEY
Type
String
Description
The user’s unique session ID. You can use this value to identify all user events within a session. When a user logs out and logs in again, a new session is started.
For example: d7DEq/ANa7nNZZVD.
TIMESTAMP
Type
String
Description
The access time of Salesforce services in GMT.
For example: 20130715233322.670.
TIMESTAMP_DERIVED
Type
DateTime
Description
The access time of Salesforce services in ISO8601-compatible format (YYYY-MM-DDTHH:MM:SS.sssZ).
For example: 2015-07-27T11:32:59.555Z. Timezone is GMT.
TYPE
Type
String
Description
Type of Salesforce page.
Possible Values
  • Appserver—Page without My Domain subdomain (for example, https://na44.salesforce.com)
  • Communities—Customer Experience Cloud site
  • Email—Email preview
  • Login—Login page (for example, https://login.salesforce.com)
  • Mydomain—Page on My Domain subdomain (for example, https://mycompany.my.salesforce.com)
  • Sites—Customer site
  • Static—Static content (for example, https://sfdcstatic.com)
  • Unknown—other type of page
UNIQUE_ID
Type
String
Description
The 32-character ID of the event log file in which the insecure external asset event data is found.
Example
44e128a5-ac7a-4c9a-be4c-224b6bf81b20
URI
Type
String
Description
The URI of the page that’s receiving the request.
For example: /home/home.jsp.
URI_ID_DERIVED
Type
ID
Description
The 18-character case insensitive ID of the URI of the page that’s receiving the request.
USER_ID
Type
Id
Description
The 15-character ID of the user who’s using Salesforce services through the UI or the API.
For example: 00530000009M943
USER_ID_DERIVED
Type
Id
Description
The 18-character case insensitive ID of the user who’s using Salesforce services through the UI or the API.
For example: 00590000000I1SNIA0.

Usage

UNIQUE_ID is used by Salesforce Customer Support to troubleshoot any issues that occur.