Alerting

Adding custom key-value pairs as part of the message in CEF format

nithin_shubhana
Explorer

Hi Team,
I would like to forward the syslog message output as CEF format and also would like to add additional custom key-value pairs and forward this message to the Thirdparty tool.

Can anyone let me know if my above need can be fulfilled by the "Splunk Real-Time Output" tool?

Thanks in advance.

Tags (2)
0 Karma

matthieu_araman
Communicator

Splunk app cef does this in a easy way (it replace Splunk realtime output app)

0 Karma

kristian_kolb
Ultra Champion

Please refrain from posting the same question several times.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...