 
					
				
		
I've installed the CEF Extraction v1.5.4 for splunk to pass CEF logs, however I still cannot extract both the custom fields and the cefKeys at the same time.  i.e. 'cefKeys' works and extracts everything OR cefLabelAfterKey/cefLabelBeforeKey extracts the custom fields but cefKeys no longer works.  How do I extract both the custom (e.g. cs1= cs1Label=) and normal (=) fields of the CEF event at the same time?
Has anyone else had this problem?
