If you want to protect fields that are part of a CEF log file, you can use the CEF payload to extract the required fields.
The properties for the Common Event Format (CEF) payload are explained in the following table.
Properties | Sub-Field | Description |
---|---|---|
Line Separator | Regex pattern to identify field separation. | |
Fields | CEF names and profile references must be selected. | |
Field Name | Comma separated list of CEF key names that need to be transformed (protected or unprotected). | |
Profile Name | Profile to be used to perform transform operations on the matched content. | |
User Comments | Additional information related to the action performed by the column processing. |