Splunk Enterprise

Where is the extracted_eventtype field in the duo_splunkapp created?

ww9rivers
Contributor

I see this "extracted_eventtype" field in many saved searches and dashboard inline searches. However, I cannot find where it is generated.

In the DUO events I do see "event_type" and "eventtype" fields. But not "extracted_eventtype". Dashboards with that field show "No results found.because that field is nowhere to be found in DUO events.

Any thoughts / pointers would be very much appreciated!

Labels (2)
0 Karma

dural_yyz
Motivator

Checking in other Answers it doesn't appear that "extracted_eventtype" is specific to DUO logs or app extractions.  Leads me to believe this is automagically generated at search time via Splunk default behavior.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...