My suggestion is you look at using the "ConvertRecord" processor for this purpose.
As your "Record Reader" you should be able to use the GrokReader to parse your syslog format.
As your "Record Writer" you have both CSV and JSON record writers.
I am not familiar with the "cef" file format and don't know of any processors or record writers that can convert to to that format. That one may requires some custom coding on your part.
If you found this answer addressed your question, please take a moment to login in and click the "ACCEPT" link.