Template for onboarding CEF data for CIM compliance

Splunk Community

Template for onboarding CEF data for CIM compliance

Template for onboarding CEF data for CIM compliance
This is a template which can be used to quickly onboard CEF-formatted data. Note that this is NOT a finished add-on, but is meant to help you create your own. Also note that some of the regular expressions used are not high performing, so it is not suggested that this be used on a high-volume sourcetype.
0 topics and 0 replies mentioned Template for onboarding CEF data for CIM compliance in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.