<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CEF Format parsing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/CEF-Format-parsing/m-p/576555#M101874</link>
    <description>&lt;P&gt;There are several apps for that. Most popular being &lt;A href="https://splunkbase.splunk.com/app/487/" target="_blank"&gt;https://splunkbase.splunk.com/app/487/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Nov 2021 06:24:40 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-11-29T06:24:40Z</dc:date>
    <item>
      <title>CEF Format parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CEF-Format-parsing/m-p/576554#M101873</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;We have logs coming in from one of the source in CEF format. How to deal CEF Format data parsing in Splunk so that it get auto converted in field value pair.&lt;/DIV&gt;&lt;DIV class=""&gt;Post that i could alias those fields basis on my datamodel need.&lt;/DIV&gt;&lt;DIV class=""&gt;Kindly suggest. Thanks in advance&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 29 Nov 2021 04:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CEF-Format-parsing/m-p/576554#M101873</guid>
      <dc:creator>pavanbmishra</dc:creator>
      <dc:date>2021-11-29T04:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: CEF Format parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/CEF-Format-parsing/m-p/576555#M101874</link>
      <description>&lt;P&gt;There are several apps for that. Most popular being &lt;A href="https://splunkbase.splunk.com/app/487/" target="_blank"&gt;https://splunkbase.splunk.com/app/487/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 06:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/CEF-Format-parsing/m-p/576555#M101874</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-29T06:24:40Z</dc:date>
    </item>
  </channel>
</rss>

