- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Where is the extracted_eventtype field in the duo_splunkapp created?

ww9rivers
Contributor
09-12-2024
08:20 PM
I see this "extracted_eventtype" field in many saved searches and dashboard inline searches. However, I cannot find where it is generated.
In the DUO events I do see "event_type" and "eventtype" fields. But not "extracted_eventtype". Dashboards with that field show "No results found." because that field is nowhere to be found in DUO events.
Any thoughts / pointers would be very much appreciated!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
dural_yyz
Motivator
09-13-2024
07:37 AM
Checking in other Answers it doesn't appear that "extracted_eventtype" is specific to DUO logs or app extractions. Leads me to believe this is automagically generated at search time via Splunk default behavior.
