Are there any capabilities to send opnsense syslogs off box in the common event format (CEF)?
Base CEF format is typically:
CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension
Base CEF format is typically:
CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension