UniversalAnomalyEventStore
Stores general anomaly events detected across the org by Salesforce Event Monitoring.
Columns
| Name | Type | References | Description |
| Id [KEY] | String | Unique identifier of the record. | |
| UniversalAnomalyEventNumber | String | Automatically generated number that identifies the anomaly event. | |
| LastModifiedDate | Datetime | Date and time when the record was last modified. | |
| LastViewedDate | Datetime | Date and time when the record was last viewed by a user. | |
| LastReferencedDate | Datetime | Date and time when the record was last referenced, such as through a lookup. | |
| EventIdentifier | String | Unique identifier of the anomaly event. | |
| UserId | String |
User.Id | ID of the user associated with this record. |
| Username | String | Username of the user associated with the anomaly event. | |
| EventDate | Datetime | Date and time when the anomaly event occurred. | |
| SessionKey | String | Key identifying the session associated with the anomaly event. | |
| LoginKey | String | Key identifying the login associated with the anomaly event. | |
| SourceIp | String | IP address that the anomaly event originated from. | |
| PolicyId | String | ID of the transaction security policy evaluated for this anomaly event. | |
| PolicyOutcome | String | Outcome of the transaction security policy evaluation. | |
| EvaluationTime | Double | Time taken to evaluate the transaction security policy. | |
| SecurityEventData | String | Additional data describing the security anomaly event. | |
| Score | Double | Score indicating the severity or confidence of the anomaly. | |
| Summary | String | Summary description of the anomaly event. | |
| AnomalySubType | String | Subtype classification of the anomaly event. | |
| SystemModstamp | Datetime | Date and time when the record was last modified by a user or by an automated process. | |
| CreatedDate | Datetime | Date and time when the record was created. |
Pseudocolumns
Pseudocolumn fields are used in the WHERE clause of SELECT statements and offer more granular control over the data returned from the data source.
| Name | Type | Description | |
| UserIdType | String | Specifies the type of the 'UserId' polymorphic field to use in the statement. | |
| UserIdExternalFieldName | String | Specifies the external field name of the 'UserId' polymorphic field to use in an INSERT/UPDATE/UPSERT statement | |
| SOQL | String | Specifies the SOQL query to execute against the Salesforce servers. If this pseudo column is set from the WHERE clause it will take precedence over the original query. | |
| ExternalIdColumn | String | Specifies the external Id column to use if performing an insert. If this value is specified, upsert will be used when the INSERT command is called. | |
| FilterScope | String | Optional scope to limit the records returned from queries. This property can take one of these values: Delegated, Everything, Mine, MineAndMyGroups, My_Territory, My_Team_Territory, or Team. |