# CEF message parsing

**URL:** <https://discuss.elastic.co/t/cef-message-parsing/318743>\
**Category:** Logstash\
**Created:** [November 11, 2022, 1:14pm UTC](https://discuss.elastic.co/t/cef-message-parsing/318743 "2022-11-11T13:14:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![d\_c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/d_c/32/113257_2.png) [@d\_c](https://discuss.elastic.co/u/d_c)\
**Post date:** [November 11, 2022, 1:14pm UTC](https://discuss.elastic.co/t/cef-message-parsing/318743/1 "2022-11-11T13:14:15Z")

</div>

Hello,

I'm using TCP Input plugin with CEF codec to receive CEF messages. Problem is, that some messages are not parsed parsed correctly. Message isn't processed as whole, but it's split at blankspace character within message.

This is my input:

```auto
input {
        tcp {
        port => 5514
        codec => cef
        }
}

```

I configured delimiter for CEF codec, and it helped to fix the issue on one instance (version 7.15.1)

```auto
input {
        tcp {
        port => 5514
        codec => cef { delimiter => "\n" }
        }
}

```

But when i tried it on other instance (version logstash 7.16.2), logstash won't process any messages in that pipeline.

Do you know what could be issue here?

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2022, 1:14pm UTC](https://discuss.elastic.co/t/cef-message-parsing/318743/2 "2022-12-09T13:14:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
