AnsweredAssumed Answered

Custom CEF Parser - Own Directory

Question asked by Stewart Gray on Jun 17, 2020
Latest reply on Jun 17, 2020 by Dave Glover



I've built a custom parser for an event source which sends logs in CEF format. To make it a bit more portable, I'd prefer not to require modifying cef-custom.xml (as per the guide - Custom CEF Parser). Is it possible to copy the logic from the cef.xml file and create new directory? This way it can be packaged and not require users to work around any existing modifications they may have already made to this file. 


I can see my event source is using 0002 from the cef file - could I just copy this logic? How would I then get the event source to match this one rather than the default CEF parser?