I see this "extracted_eventtype" field in many saved searches and dashboard inline searches. However, I cannot find where it is generated.
In the DUO events I do see "event_type" and "eventtype" fields. But not "extracted_eventtype". Dashboards with that field show "No results found." because that field is nowhere to be found in DUO events.
Any thoughts / pointers would be very much appreciated!
Checking in other Answers it doesn't appear that "extracted_eventtype" is specific to DUO logs or app extractions. Leads me to believe this is automagically generated at search time via Splunk default behavior.