I would like to forward the syslog message output as CEF format and also would like to add additional custom key-value pairs and forward this message to the Thirdparty tool.
Can anyone let me know if my above need can be fulfilled by the "Splunk Real-Time Output" tool?
Thanks in advance.
Splunk app cef does this in a easy way (it replace Splunk realtime output app)
Please refrain from posting the same question several times.