I am looking for a way to transmit Custom Log Fields via Syslog (CEF format).
Currently it seems that you can only transfer the default log fields:
But I would like to transfer additional log information, which I write e.g. via a content filter or message filter.
As a workaround it would be sufficient if I could see in the transmitted log which content filter is '"matched", but this is apparently not possible, because you can only see if a CF is matched (ESACFVerdict=MATCH).
Please let me know if there are possibilities.