Common Event Format
Common Event Format (CEF) is an extensible, text-based, high-performance format designed to support multiple device types in the simplest manner possible. CEF defines the syntax for log records comprised of a standard header and a variable extension, formatted as key-value pairs. CEF uses syslog as a transport mechanism. CEF uses the following format as exemplified below. It is comprised of a syslog prefix, a header, and an extension.
For example:
Jan 18 11:07:53 host CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|[Extension]
Dec 19 08:31:10 host CEF:0|Security|threatmanager|1.0|101|out of hours workstation login|10|suser=hbutler src=activedirectorydomain ip=10.1.76.224