AllI was able to solve the issue by using customLog.Solution:LogFormat
"{ \"time\":\"%t\", \"remoteIP\":\"%a\", \"host\":\"%V\",
\"urlpath\":\"%U\", \"query\":\"%q\", \"method\":\"%m\",
\"status\":\"%>s\", \"True-Client-IP\":\"%{True-Client-IP}i\",
\"userAgent\":\"%{User-agent}i\", \"referer\":\"%{Referer}i\" }"
splunkCustomLog /cq/log/exp-splunk.log splunk