What is the best practice of importing CEF files into Splunk, retrieved from Forcepoint CASB's siem tool? We have a Windows server that is downloading the cef files from Forcepoint CASB into into its local directories. We have a Splunk universal forwarder installed on this server as well. We also have a heavy forwarder, search head and three indexers running 8.0.5.
... View more