I tried many times to import raw data (CEF) from another SIEM (just to test) and configured to send data to a specific port with zero results.
Any ideas on what is the correct procedure to do this?
you can take data directly from CEF to splunk, there is also an app for it:
installation and configuration here:
what is the other SIEM tool?