Getting Data In

Is it possible to send logs in CEF format or raw logs by syslog from Splunk to a third party system?

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I have to send logs to a third party system by syslog.
I configured my system and I'm able to send events to a third party system, but the receiver needs to have logs in raw or CEF format and Splunk sends syslogs in a different format.

Is it possible to change the logs format or to send raw logs by syslog?

Thank you.
Bye.
Giuseppe

0 Karma
1 Solution

bobnieuwenhuis
Explorer

Guiseppe,

You could use App for CEF https://splunkbase.splunk.com/app/1847/
We are using it to send data in CEF format to ArcSight, only downside to this is, you have to use a standalone searchhead, as you can't use it in a searchheadcluster.

Hope this answers your question.
Bob

View solution in original post

0 Karma

bobnieuwenhuis
Explorer

Guiseppe,

You could use App for CEF https://splunkbase.splunk.com/app/1847/
We are using it to send data in CEF format to ArcSight, only downside to this is, you have to use a standalone searchhead, as you can't use it in a searchheadcluster.

Hope this answers your question.
Bob

0 Karma

harehabibi
New Member

hi
after installation App fo CEF , how config outputs.conf (\Splunk\etc\apps\splunk_app_cef\default\outputs.conf) and other config file
i want to send some log generated by Splunk_stream to arcsight
on

0 Karma

Shyngys_Bolatbe
Engager

How to save new field, which created with |cefkv command?
When I don't use |cefkv command my new fileds disappear.
I want to save fields in index with events

0 Karma

Shyngys_Bolatbe
Engager

How to save new field, which created with |cefkv command?
When I don't use |cefkv command my new fileds disappear.
I want to save fields in index with events

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...