<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Extracting fields based on eventtype? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45589#M10832</link>
    <description>&lt;P&gt;It is currently possible to setup field extractions based on an &lt;CODE&gt;eventtype&lt;/CODE&gt; definition, but it sounds like this may not always be supported.  I've been using this feature since Splunk 3.3 or 3.4 (when we first started using splunk). But based on some discussions with the engineers, it sounds like this feature may go away or be depreciated and it sounds like it's currently already a highly-discouraged feature.&lt;/P&gt;

&lt;P&gt;I recently notice the following message in my &lt;CODE&gt;info.csv&lt;/CODE&gt; in the job dispatch folder.  (Seem's like it's a "DEBUG" message which is probably why I haven't seen it from the search UI)&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Message:&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;BLOCKQUOTE&gt;
    &lt;P&gt;Extracting fields based on eventtype is not supported during the main search. Please see splunk documentation for more information.&lt;/P&gt;
  &lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;However I'm unable to find the related documentation.  Anyone know the official answer to whether or not this feature is truly going away, and how soon?  Would the message be more accurately stated:  "searching for extracted fields based on eventtype is not supported during the main search"?  Or is there some other meaning here?&lt;/P&gt;

&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;I get that technically field extractions based on eventtypes is a complex and potentially confusing feature.  I have many different types of events with unique field extractions for a single source/sourcetype; so I'm not sure what the recommendation is on how to replace my existing eventtype-based field extractions....&lt;/P&gt;</description>
    <pubDate>Wed, 08 Sep 2010 04:20:39 GMT</pubDate>
    <dc:creator>Lowell</dc:creator>
    <dc:date>2010-09-08T04:20:39Z</dc:date>
    <item>
      <title>Extracting fields based on eventtype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45589#M10832</link>
      <description>&lt;P&gt;It is currently possible to setup field extractions based on an &lt;CODE&gt;eventtype&lt;/CODE&gt; definition, but it sounds like this may not always be supported.  I've been using this feature since Splunk 3.3 or 3.4 (when we first started using splunk). But based on some discussions with the engineers, it sounds like this feature may go away or be depreciated and it sounds like it's currently already a highly-discouraged feature.&lt;/P&gt;

&lt;P&gt;I recently notice the following message in my &lt;CODE&gt;info.csv&lt;/CODE&gt; in the job dispatch folder.  (Seem's like it's a "DEBUG" message which is probably why I haven't seen it from the search UI)&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Message:&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
  &lt;BLOCKQUOTE&gt;
    &lt;P&gt;Extracting fields based on eventtype is not supported during the main search. Please see splunk documentation for more information.&lt;/P&gt;
  &lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;However I'm unable to find the related documentation.  Anyone know the official answer to whether or not this feature is truly going away, and how soon?  Would the message be more accurately stated:  "searching for extracted fields based on eventtype is not supported during the main search"?  Or is there some other meaning here?&lt;/P&gt;

&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;I get that technically field extractions based on eventtypes is a complex and potentially confusing feature.  I have many different types of events with unique field extractions for a single source/sourcetype; so I'm not sure what the recommendation is on how to replace my existing eventtype-based field extractions....&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2010 04:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45589#M10832</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-09-08T04:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields based on eventtype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45590#M10833</link>
      <description>&lt;P&gt;We intend to leave the feature in in its "half-working" mode until we fix it or provide a better technique for extracting fields based on a dynamic condition. You are correct in saying that the message is more accurately stated as that you can't search for eventtype-extracted fields.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2010 10:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45590#M10833</guid>
      <dc:creator>Stephen_Sorkin</dc:creator>
      <dc:date>2010-09-08T10:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields based on eventtype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45591#M10834</link>
      <description>&lt;P&gt;This is really neeeded, on shared plateform, the sourcetype is the same for everybody, and there are a lot of sources and host... so how to affect the extraction, if it is not possible to affect it to a source=&lt;EM&gt;key&lt;/EM&gt; or an eventtype...&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2013 15:19:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45591#M10834</guid>
      <dc:creator>sbsbb</dc:creator>
      <dc:date>2013-04-30T15:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields based on eventtype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45592#M10835</link>
      <description>&lt;P&gt;Hi Lowell,&lt;/P&gt;

&lt;P&gt;Does this problem has been fixed in the latest version ?&lt;/P&gt;

&lt;P&gt;I am interested in implementing a similar solution even-type based regex. Can you pls advise how you have implemented this ?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Kind Regards&lt;/P&gt;

&lt;P&gt;KK&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 00:29:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45592#M10835</guid>
      <dc:creator>KarunK</dc:creator>
      <dc:date>2013-08-26T00:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields based on eventtype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45593#M10836</link>
      <description>&lt;P&gt;Stephen, are there any better techniques introduced in the recent versions? I have a similar problem where I have to define the eventtype before field extraction.&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2014 22:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45593#M10836</guid>
      <dc:creator>ananthkumar12</dc:creator>
      <dc:date>2014-12-29T22:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Extracting fields based on eventtype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45594#M10837</link>
      <description>&lt;P&gt;10 years later..... &lt;EM&gt;crickets&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 16:20:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extracting-fields-based-on-eventtype/m-p/45594#M10837</guid>
      <dc:creator>Eric_Mcknight</dc:creator>
      <dc:date>2019-01-17T16:20:10Z</dc:date>
    </item>
  </channel>
</rss>

