# CEF module and decode\_cef processor

**URL:** <https://discuss.elastic.co/t/cef-module-and-decode-cef-processor/245430>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 18, 2020, 1:41pm UTC](https://discuss.elastic.co/t/cef-module-and-decode-cef-processor/245430 "2020-08-18T13:41:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![anon56147639](https://avatars.discourse-cdn.com/v4/letter/a/a8b319/32.png) [@anon56147639](https://discuss.elastic.co/u/anon56147639)\
**Post date:** [August 18, 2020, 1:41pm UTC](https://discuss.elastic.co/t/cef-module-and-decode-cef-processor/245430/1 "2020-08-18T13:41:56Z")

</div>

Hi everyone,

I have a question about the CEF module in Filebeat. Can it only be used to listen to incoming syslog traffic or can the module also read from locally stored files?  
I'm asking this because there is no definition for files paths like "var.paths:" mentioned in the reference guide.  
[https://www.elastic.co/guide/en/beats/filebeat/7.x/filebeat-module-cef.html](https://www.elastic.co/guide/en/beats/filebeat/7.x/filebeat-module-cef.html)

If I can't use the CEF module for this purpose, can I then just use the decode\_cef processor by adding code to the filebeat.yml?  
Like here: [https://www.elastic.co/guide/en/beats/filebeat/7.x/processor-decode-cef.html](https://www.elastic.co/guide/en/beats/filebeat/7.x/processor-decode-cef.html)

Any help is appreciated 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 15, 2020, 3:42pm UTC](https://discuss.elastic.co/t/cef-module-and-decode-cef-processor/245430/2 "2020-09-15T15:42:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
