<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interactive field extractor in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22693#M177428</link>
    <description>&lt;P&gt;Thanks dwaddle.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Aug 2012 16:13:43 GMT</pubDate>
    <dc:creator>jangid</dc:creator>
    <dc:date>2012-08-14T16:13:43Z</dc:date>
    <item>
      <title>Interactive field extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22689#M177424</link>
      <description>&lt;P&gt;my search is based on the eventtype="someevents" and now I want to extract field and I want to restrict my fields extraction based on eventtype.&lt;/P&gt;

&lt;P&gt;in IFX [&lt;A href="http://mjserver:8000/en-US/ifx?sid=1343810123.69&amp;amp;offset=0&amp;amp;namespace=MyApp"&gt;http://mjserver:8000/en-US/ifx?sid=1343810123.69&amp;amp;offset=0&amp;amp;namespace=MyApp&lt;/A&gt;] page I can not see eventtype listing in Restrict extraction to: combo box.&lt;/P&gt;

&lt;P&gt;How do I add eventtype in that combo box&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2012 09:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22689#M177424</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-08-01T09:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Interactive field extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22690#M177425</link>
      <description>&lt;P&gt;Any update?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2012 10:02:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22690#M177425</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-08-10T10:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Interactive field extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22691#M177426</link>
      <description>&lt;P&gt;Is it possible to change IFX restriction?if Yes how do I?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2012 09:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22691#M177426</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-08-13T09:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Interactive field extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22692#M177427</link>
      <description>&lt;P&gt;This is not possible in the current release (4.3).  It is not a limitation of the interactive extractor, but of Splunk itself.  Field extractions can only be defined for a sourcetype, source, or host.  You cannot today define an extraction scope to an eventtype.  &lt;/P&gt;

&lt;P&gt;There is little additional processing cost (if any) for doing extraction based on the sourcetype(s) in question.&lt;/P&gt;

&lt;P&gt;You can, of course, feel free to submit an enhancement request, see &lt;A href="http://splunk-base.splunk.com/answers/4844/how-can-i-submit-an-enhancement-request"&gt;http://splunk-base.splunk.com/answers/4844/how-can-i-submit-an-enhancement-request&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2012 15:32:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22692#M177427</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2012-08-14T15:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Interactive field extractor</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22693#M177428</link>
      <description>&lt;P&gt;Thanks dwaddle.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Aug 2012 16:13:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Interactive-field-extractor/m-p/22693#M177428</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-08-14T16:13:43Z</dc:date>
    </item>
  </channel>
</rss>

