Hi I have created a custom Event type and I would like to perform some field extraction based on the new event type, but I can't do it. I can oly extract based on the Host, Source and sourcetype
Yes, host source sourcetype only.
See http://docs.splunk.com/Documentation/Splunk/5.0.2/Admin/Propsconf - specifically, the section explaining .
View solution in original post
Eventtype produced under the conditions of a particular field >>
index=AAA (keyworld1 OR kewyorld2) AND (keyworld3)
index=AAA (SpecificField="keyworld1" OR SpecificField="kewyorld2") AND (Specific_Field="keyworld3")