Customers using the QRadar Salesforce Security integration now have an additional authentication option for their Salesforce application.
Based on customer requests, QRadar now supports Salesforce External Client Apps. Client Credentials Flow is now the default authentication method for new configurations.
When creating or editing a Salesforce Security log source, customers can select the authentication method that matches their Salesforce application:

Customers can select the authentication method that matches their Salesforce application configuration.
Customers using an existing Connected App with Password Authentication can continue to provide details such as the Username, Password, Security Token, Client ID, and Secret ID.

Existing Connected App configurations can continue to use Password Authentication.
Customers using Client Credentials Flow can provide the Client ID and Secret ID associated with their Salesforce application. The Username, Password, and Security Token fields are not displayed when this authentication method is selected.

Client Credentials Flow displays the Client ID and Secret ID fields without requiring a username, password, or security token in the QRadar log source configuration.
This enhancement provides customers with an authentication option for Salesforce External Client Apps while continuing to support existing Connected App configurations. It also helps customers prepare for the transition from the Username-Password OAuth flow to Client Credentials Flow.
Learn more
For an overview of the Salesforce Security integration, see:
Salesforce Security
For details about the authentication methods and log source parameters, see:
Salesforce REST API log source parameters for Salesforce Security
Note
Customers upgrading to the latest Salesforce protocol can continue using their existing Connected App configured with the Username-Password OAuth flow. Existing configurations will continue to work.
However, Salesforce has officially announced the retirement of the OAuth 2.0 Username-Password Flow for Connected Apps. Therefore, we recommend that customers migrate to the Client Credentials Flow authentication method in QRadar. This will ensure a seamless transition and uninterrupted communication between Salesforce and QRadar as Salesforce phases out support for the Username-Password flow.