Hi Rebecca,
Since you mention you installed BOTH CEF and AMA, it makes me think you're getting the old (OMS + CEF) and new (just AMA) methods mixed up.
I have a blog on the setup here:
So my suggestion is:
- uninstall your agent(s)
- follow the blog to install Arc.
- Create a DCR which will apply the AMA agent (no need to install AMA and CEF directly - the DCR will do this via the Arc agent)
- Enable the AMA with CEF data collector in Sentinel which will configure AMA to process CEF.
- Use the troubleshooting script at the bottom of my blog - if you get all OKs from the script you're on a very good path.
Note: you are correct in not using LEEF - only IBM uses that for QRadar - it's not a format that was widely adopted by anyone.