Splunk Enterprise

Where is the extracted_eventtype field in the duo_splunkapp created?

ww9rivers
Contributor

I see this "extracted_eventtype" field in many saved searches and dashboard inline searches. However, I cannot find where it is generated.

In the DUO events I do see "event_type" and "eventtype" fields. But not "extracted_eventtype". Dashboards with that field show "No results found.because that field is nowhere to be found in DUO events.

Any thoughts / pointers would be very much appreciated!

Labels (2)
0 Karma

dural_yyz
Motivator

Checking in other Answers it doesn't appear that "extracted_eventtype" is specific to DUO logs or app extractions.  Leads me to believe this is automagically generated at search time via Splunk default behavior.

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...