Hi @mara7
Try running the following command to send a demo message,
logger -p syslog.warn -P 514 -n 127.0.0.1 --rfc3164 -t CEF "0|Mock-test|MOCK|common=event-format-test|end|TRAFFIC|1|rt=$common=event-formatted-receive_time"
If the message is successful, then the issue could be with your DCR configuration. You'll need to add additional facilities.
In your output, it appears you're only pulling syslog and user. If your DCR is configured for additional facilities and you still don't see the demo message, then comment down below. We'll need to work more closely with you.