Hi Andreas,
Thank you for the response. Suggested link tell us about different types of events will be appeared in SIEM integration. Our customer is looking for the fields of each event type.
As you said, event format is syslog and most of them are self-explanatory but still cannot get some of them.
In the sample event, looks like it is 'pipe' separated format the first field is then "Mar 1 10:36:18 S137AF5.netf.adint.ssa.gov S137AF5 CEF Ver1.0". It has date and time with our distribution server name appeared in FQDN and in short name with additional information about CEF version. So, in short, first field provides more than one form of information.
Also, there are fields like "1" and "4" which are not self-explanatory.
If you can help me to get information on all fields would be great help.
Thanks,
Pravin Bhole