Why can't I do field extraction from a previously built eventtype? I can limit extraction of sourcetype, but not to eventtype?
I feel like event types and custom field extraction are marriage made in heaven, but somehow splunk UI does not let me do achieve it...
I am sure there is some kinda hack in the conf files to do it... can anybody enlighten me?
You can do it via the props.conf/transforms.conf config files (the stanza name starts with eventtype::, similar to source:: or host::) but it is not a fully supported configuration. See Sorkin's answer here.
View solution in original post