Just one aspect with my above issue, if you can check the community link I'd pasted above they say there is some parsing field issue for forwarding these logs by the approach which we are looking forward.
Someone has mentioned about CIM data modelling, this is the new concept for me today.
As per my quick reading I found this is used to help Splunk to understand and identify logs with its fields.
But just this needs to know where this CIm modelling will be used ahead, I mean in UF or HF/indexer or both???