↳ GitHub sourceConnector

Salesforce Marketing Cloud (via Codeless Connector Framework)

Description

Collects audit events and security events from the Salesforce Marketing Cloud [Audit Trail API](https://developer.salesforce.com/docs/marketing/marketing-cloud/references/mc_rest_audit?meta=Summary). Provides visibility into user activities, system changes, and login events.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Salesforce Marketing Cloud API access
Access to the Salesforce Marketing Cloud API through an Installed Package is required.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Salesforce Marketing Cloud to Microsoft Sentinel
Follow the [Salesforce Marketing Cloud documentation](https://developer.salesforce.com/docs/marketing/marketing-cloud/guide/install-packages.html) to create an Installed Package with the **Data | Tracking Event | Read** permission scope. Note your tenant-specific REST API and Auth base URLs from the Installed Packages section in Setup.
Manage Salesforce Connections
Add, view, and delete Salesforce connections
Add Connection
Configure API Connection
Base Configuration
Configure your Salesforce API connection
Connection Alias
Enter a unique alias to identify this Salesforce connection. **Important**: Use different aliases for each domain. To update an existing connection, use the same alias or delete and create with the same alias. To replace a connection, delete the old one and create a new one with a new alias.
Query interval (in minutes)
5
10
15
20
30
60
REST API Base URL
Enter your tenant-specific REST API Base URL without trailing slash (Example, https://{subdomain}.rest.marketingcloudapis.com). Find it in the Installed Packages section in Setup.
Auth Base URL
Include your subdomain in the Auth Base URL. This is different from your REST API Base URL.
Data Types
Audit Events - user activities and system changes
Security Events - login attempts and authentication
API Credentials
Configure Installed Package credentials for API access
Select the type of Installed Package you created in Marketing Cloud. **Enhanced Package** uses the OAuth 2.0 client credentials flow against the `/v2/token` endpoint. **Legacy Package** uses the `/v1/requestToken` endpoint. Both require the Consumer Key (Client Id) and Consumer Secret from your Installed Package.
Package Type
Select the Installed Package type and enter its credentials
Package Type
Enhanced Package
Consumer Key
Consumer Secret
Legacy Package
Consumer Key
Consumer Secret

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
SalesforceMktCloudConnector
Additional source files 2Solutions/Salesforce Service Cloud/Data Connectors/SalesforceMarketingCloudConnector_CCF/SalesforceMarketingCloud_ConnectorDefinition.jsonsource ↗Solutions/Salesforce Service Cloud/Data/Solution_TSalesforceCloudtemplateSpec.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.