I want to forward logs in CEF format from Splunk to a 3rd party system over TCP. To achieve this, I'm using Splunk app for CEF. I went through the steps (Select Data, Map Fields, Create Static Fields, Define Output Groups, Save Search) but at the Save search step when i click Next to go to the next step i get the following error:
I tried the generated query in the search & it's working fine. I tried reinstalling the app but the error is still the same.
Appreciate any help I can get. Also i'm open to alternative methods to forward alerts in CEF format from Splunk to external systems over TCP.