We send CEF/Syslog events to Splunk over UDP. This article explains how to configure Splunk to receive events from JATP.
Splunk Home -> Data -> Add Data -> Choose a Data Source -> From a UDP port. Then you will see an "Add New" page.
->
Enter the following: UDP port : 514 Source Name Override : leave it empty Set Source type : Manual Source type : You can enter CEF/Syslog
UDP port : 514 Source Name Override : leave it empty Set Source type : Manual Source type : You can enter CEF/Syslog
Click Save
Go to Data Inputs -> UDP to verify the config has been enabled.
Config -> Notifications -> SIEM Settings
Click Add New SIEM Connector
Select the appropriate data type and format. Syslog and CEF are both supported. However, CEF format is preferred.
Enter the hostname as your Splunk server and the port number as 514.