Adding custom key-value pairs as part of the message in CEF format


Hi Team,
I would like to forward the syslog message output as CEF format and also would like to add additional custom key-value pairs and forward this message to the Thirdparty tool.

Can anyone let me know if my above need can be fulfilled by the "Splunk Real-Time Output" tool?

Thanks in advance.

Tags (2)
0 Karma


Splunk app cef does this in a easy way (it replace Splunk realtime output app)

0 Karma

Ultra Champion

Please refrain from posting the same question several times.

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!