Troubleshoot the Workday Activity Logging connector
This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Workday Activity Logging from the Previews page. See Manage Databricks previews.
Resolve common Workday Activity Logging connector errors, including OAuth authentication failures, missing System Auditing permissions, and unavailable historical events.
For general troubleshooting guidance that applies to all managed ingestion pipelines, see Troubleshoot managed ingestion pipelines.
Pipeline fails to authenticate
Cause: The OAuth client values or refresh token in the Unity Catalog connection aren't valid, or OAuth 2.0 isn't enabled for the Workday tenant.
Solution:
- Confirm that OAuth 2.0 Clients Enabled is selected in Edit Tenant Setup - Security.
- Confirm that the Client ID and Client Secret in the connection match the registered API client.
- Confirm that the Refresh token was generated for the integration system user and hasn't expired or been revoked.
- Confirm that the Instance URL contains only the instance host, without a scheme or path, and that the Tenant name is correct.
For details, see Configure authentication to Workday.
Pipeline can't access activity log data
Cause: The integration system security group doesn't have the required permissions for the System Auditing domain, or pending security policy changes weren't activated.
Solution:
- Confirm that the integration system user belongs to the Integration System Security Group (Unconstrained) used by the API client.
- Confirm that the security group has View access under Report/Task Permissions for the System Auditing domain.
- Confirm that the security group has Get access under Integration Permissions for the System Auditing domain.
- Activate pending security policy changes.
Older events are missing after a checkpoint issue
Cause: The pipeline checkpoint is older than the historical window available to the connector. The connector can fetch only up to the previous 30 days of events.
Solution:
Resume or refresh the pipeline. Events older than the available 30-day window can't be recovered by the connector.