I wish you posted your cef properties file.
Bummer that the arcsight flex-connector install doesn't include any sample properties files (as far as I can tell) for the cef log.
I am using "ArcSight FlexConnector Multiple Folder File" connector with a type of "cef" (option 3).
I don't understand how to do the mapping. Is there a properties file for the mapping? I.e. it is not just a straight cef-to-cef pass-through with no mapping?
I can do a regex parsing, and it will parse the seven header fields of the CEF record, but then the remainer key=value fields are not parsed.
Or I can do a cef parsing, in which case the CEF header fields are not parsed and end up being a bunch of vertical bars on the output-side.
Since CEF is a basic arcsight format, I would think that they have basic support for it?