I have a lot of CEF Events in my Splunk Server and would like to install CEFUtils - Common Event Format Extraction Utilities. Normally decompress the file and place it in \Splunk\etc\apps.
But I never know if I have to install it on the searchhead or on the indexer. Is there a way
install it on the search head since it reports the fields you want,
on the indexer (OR splunk forwarder if you use one) you make the necessary changes to the relevant stanza for time recognition.
[stanzaname]
TIME_PREFIX = \s(end|rt)=
TIME_FORMAT = %10S%3n
MAX_TIMESTAMP_LOOKHEAD = 350
the max timestamp lookahead length changes according to the CEF data received
install it on the search head since it reports the fields you want,
on the indexer (OR splunk forwarder if you use one) you make the necessary changes to the relevant stanza for time recognition.
[stanzaname]
TIME_PREFIX = \s(end|rt)=
TIME_FORMAT = %10S%3n
MAX_TIMESTAMP_LOOKHEAD = 350
the max timestamp lookahead length changes according to the CEF data received