<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible with Splunk Enterprise to input JSON logs into the instance and transform them to CEF format? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/519456#M3413</link>
    <description>&lt;P&gt;Hello!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is it possible with Splunk Enterprise to input JSON logs into the instance and transform them to CEF format?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 17:45:32 GMT</pubDate>
    <dc:creator>aneuharth93</dc:creator>
    <dc:date>2023-02-23T17:45:32Z</dc:date>
    <item>
      <title>Is it possible with Splunk Enterprise to input JSON logs into the instance and transform them to CEF format?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/519456#M3413</link>
      <description>&lt;P&gt;Hello!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is it possible with Splunk Enterprise to input JSON logs into the instance and transform them to CEF format?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 17:45:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/519456#M3413</guid>
      <dc:creator>aneuharth93</dc:creator>
      <dc:date>2023-02-23T17:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: JSON to CEF Format</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/519457#M3414</link>
      <description>&lt;P&gt;Please tell us more about what you want to do?&amp;nbsp; What is the use case?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 14:43:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/519457#M3414</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-14T14:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: JSON to CEF Format</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/519462#M3418</link>
      <description>&lt;P&gt;Sure thing!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Currently, I am ingesting logs from Slack which come in JSON format. Our current SIEM solution does not have a good way to parse these. However, we can ingest CEF/syslog formats easily.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So I am looking to ingest Slack logs, transform to a different data format, and forward it to our SIEM.&lt;BR /&gt;&lt;BR /&gt;Please let me know if you need any further information, but that's the gist of it.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2020 14:56:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/519462#M3418</guid>
      <dc:creator>aneuharth93</dc:creator>
      <dc:date>2020-09-14T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: JSON to CEF Format</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/631925#M15479</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If you have the ability to output a file in CEF format, you may be able to use Splunk to output the file and then use a parser script to generate the CEF logs that you need. The feasibility of this approach depends on the specific use case and the logs that you are ingesting. This is a solution that I have developed in the past to convert json format for cisco logs to CEF&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://medium.com/@tamirsuliman/convert-elk-json-format-to-cef-format-41730be67f36" target="_blank"&gt;https://medium.com/@tamirsuliman/convert-elk-json-format-to-cef-format-41730be67f36&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 22:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/631925#M15479</guid>
      <dc:creator>allamiro</dc:creator>
      <dc:date>2023-02-22T22:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: JSON to CEF Format</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/631994#M15483</link>
      <description>&lt;P&gt;it would b easier if you post a sample message of the json logs. you getting from slack&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 10:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Is-it-possible-with-Splunk-Enterprise-to-input-JSON-logs-into/m-p/631994#M15483</guid>
      <dc:creator>allamiro</dc:creator>
      <dc:date>2023-02-23T10:16:34Z</dc:date>
    </item>
  </channel>
</rss>

