If you have the ability to output a file in CEF format, you may be able to use Splunk to output the file and then use a parser script to generate the CEF logs that you need. The feasibility of this approach depends on the specific use case and the logs that you are ingesting. This is a solution that I have developed in the past to convert json format for cisco logs to CEF https://medium.com/@tamirsuliman/convert-elk-json-format-to-cef-format-41730be67f36
... View more