All Apps and Add-ons

List of all possible output fields for Splunk App for CEF

Splunk Employee
Splunk Employee

Where can one find a list of all possible output fields for the Splunk App for CEF?

Jacob
Sr. Technical Support Engineer
Tags (1)
1 Solution

Splunk Employee
Splunk Employee

There is a lookup file located in the app which contains all the output fields. This file is located in:

  • $SPLUNKHOME/etc/apps/splunkapp_cef/lookups/

The file name is cef_inventory.csv.

Jacob
Sr. Technical Support Engineer

View solution in original post

Splunk Employee
Splunk Employee

There is a lookup file located in the app which contains all the output fields. This file is located in:

  • $SPLUNKHOME/etc/apps/splunkapp_cef/lookups/

The file name is cef_inventory.csv.

Jacob
Sr. Technical Support Engineer

View solution in original post