All Apps and Add-ons

Splunk app for cef: "Argument "action.cefout2" is not supported by this handler"

ezzeldinadel
New Member

I want to forward logs in CEF format from Splunk to a 3rd party system over TCP. To achieve this, I'm using Splunk app for CEF. I went through the steps (Select Data, Map Fields, Create Static Fields, Define Output Groups, Save Search) but at the Save search step when i click Next to go to the next step i get the following error: 

ezzeldinadel_0-1650490334058.png

I tried the generated query in the search & it's working fine. I tried reinstalling the app but the error is still the same.

Appreciate any help I can get. Also i'm open to alternative methods to forward alerts in CEF format from Splunk to external systems over TCP.

Labels (3)
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...