All Apps and Add-ons

CEF Extraction Add-on for Splunk - Not Working

hinds89
New Member

I've installed the CEF Extraction v1.5.4 for splunk to pass CEF logs, however I still cannot extract both the custom fields and the cefKeys at the same time. i.e. 'cefKeys' works and extracts everything OR cefLabelAfterKey/cefLabelBeforeKey extracts the custom fields but cefKeys no longer works. How do I extract both the custom (e.g. cs1= cs1Label=) and normal (=) fields of the CEF event at the same time?
Has anyone else had this problem?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...