← Browse all tablesLoading table information…
SalesforceAuditTrail Schema
Table description
| TableSection |
TableType |
TableSectionName |
Description |
|
|
Other hunting tables |
The Setup Audit Trail table contains logs from the Salesforce Audit Trail API that have been ingested into Microsoft Sentinel. |
Schema
| Name |
Description |
Type |
| _BilledSize |
|
Double |
| _IsBillable |
|
String |
| Action |
The action performed. |
String |
| CreatedByContext |
The context in which the user made the change. |
String |
| CreatedByEmail |
The email of the user who made the change. |
String |
| CreatedById |
The ID of the user who made the change. |
String |
| CreatedByIssuer |
The issuer of the user’s identity. |
String |
| CreatedByName |
The name of the user who made the change. |
String |
| CreatedByUsername |
The username of the user who made the change. |
String |
| CreatedDate |
The date and time when the change was made. |
DateTime |
| DelegateUser |
The user who delegated the change. |
String |
| Display |
A user-friendly display name for the change. |
String |
| Id |
The unique identifier for the audit trail entry. |
String |
| SalesforceDomain |
Salesforce host/domain configured for this connection; hard-coded on every record so hosts can be differentiated. |
String |
| Section |
The section of the Salesforce setup that was changed. |
String |
| SourceSystem |
|
String |
| TenantId |
Unique identifier of the tenant into which the data connector ingests data. |
String |
| TimeGenerated |
The timestamp (in UTC) when the log entry was generated. |
DateTime |
| Type |
The name of the table |
String |
Schema changes
| Date |
Action |
| 2026-10-07 |
Table added to tracking |