Default Version 1.1.0
July 23, 2026
July 23, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2
Log in to rate this app
CEF Formatted fields/data Parser as a Splunk Search Command. It will extract CEF Headers and other extended fields from the event in Splunk. It will be used on any field at the search time in a search query. You can extract fields with simple search command as this in your query. | cefparser field="cef_data"
Log in to report this app listing.