I have successfully installed the Splunk App for CEF to our stand alone test server
and I try to select a data model according to this document
However, I could not find any drop down menu, where can I select the data model?
Here is the screen when I click the New CEF output.
Sorry, I found that our splunk version (6.1) is not supported by Splunk App for CEF 2.0.0
View solution in original post
Please upgrade to the latest version of Splunk and also install the Common Information Model App from apps.splunk.com.
Thanks, I'm not aware to install the CIM app!