what is the cef format? if that is a binary form, yes, that cannot be done. if that is the name of a syslog output format (similar to WELF), which I think it may be, you should be able create this filter to contain the data you are looking to host, and in the order you want, at System>Log/Monitoring>Events|User Access|Admin Access>Filters and then setting your syslog output to use that filter. You can, if desired, also set this as the on-box display filter.
For any questions or assistance, please contact our support team
... View more