Skip to content

Common Event Format


ArcSight's Common Event Format (CEF) is an open log management standard. If one of your applications or devices is not covered by one of the other intakes we support but can produce logs in CEF you can use this intake.

Still we recommend using an intake tailored to your specific application or device, even with CEF, in order to ensure you get the most out of your logs. If an intake is missing, please contact us.


As of now, the main solution to collect CEF logs leverages the Rsyslog recipe. Please share your experiences with other recipes by editing this documentation.


Please refer to the documentation of your vendor to forward events to your rsyslog server. The reader is also invited to consult the Rsyslog Transport documentation to forward these logs to SEKOIA.IO.

Further Reading