Hi, Salesforce is mainly a public SaaS service (unless you are talking about private connect Salesforce) hence its traffic is not taking the SDWAN overlay. The rule you're are showing applies to SDWAN VPN traffic so it has nothing to do with internet traffic.
Every MX sends non VPN traffic as Local Break Out over the underlay path when it has no vpn route to destination. It then takes the default route present in the underlay table. In your case you have two wan interfaces (I supposed both are internet access circuits). Provided your primary uplink is uplink2, then by default Salesforce would take wan2 uplink. In order to force this traffic to take uplink1 underlay, you should configure the proper rules in the table you can see above the one you are showing, up in the same pane. Table: Flow preference/Internet traffic.
The problem here is you should configure one rule per each Salesforce prefix you could be using based in your geography. This table does not support domain names but only IP prefixes.
HTH.
Regards,
Chema.