Splunk Enterprise

Where is the extracted_eventtype field in the duo_splunkapp created?

ww9rivers
Contributor

I see this "extracted_eventtype" field in many saved searches and dashboard inline searches. However, I cannot find where it is generated.

In the DUO events I do see "event_type" and "eventtype" fields. But not "extracted_eventtype". Dashboards with that field show "No results found.because that field is nowhere to be found in DUO events.

Any thoughts / pointers would be very much appreciated!

Labels (2)
0 Karma

dural_yyz
Builder

Checking in other Answers it doesn't appear that "extracted_eventtype" is specific to DUO logs or app extractions.  Leads me to believe this is automagically generated at search time via Splunk default behavior.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...