Skip to content

Instantly share code, notes, and snippets.

@jamesfed
Created June 4, 2020 08:22
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
Star You must be signed in to star a gist
Embed
What would you like to do?
rule "Process CEF"
when
true
then
set_fields(parse_cef(to_string($message.message), false));
end
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment