my search is based on the eventtype="someevents" and now I want to extract field and I want to restrict my fields extraction based on eventtype.
in IFX [http://mjserver:8000/en-US/ifx?sid=1343810123.69&offset=0&namespace=MyApp] page I can not see eventtype listing in Restrict extraction to: combo box.
How do I add eventtype in that combo box
This is not possible in the current release (4.3). It is not a limitation of the interactive extractor, but of Splunk itself. Field extractions can only be defined for a sourcetype, source, or host. You cannot today define an extraction scope to an eventtype.
There is little additional processing cost (if any) for doing extraction based on the sourcetype(s) in question.
You can, of course, feel free to submit an enhancement request, see http://splunk-base.splunk.com/answers/4844/how-can-i-submit-an-enhancement-request
This is not possible in the current release (4.3). It is not a limitation of the interactive extractor, but of Splunk itself. Field extractions can only be defined for a sourcetype, source, or host. You cannot today define an extraction scope to an eventtype.
There is little additional processing cost (if any) for doing extraction based on the sourcetype(s) in question.
You can, of course, feel free to submit an enhancement request, see http://splunk-base.splunk.com/answers/4844/how-can-i-submit-an-enhancement-request
Thanks dwaddle.
Is it possible to change IFX restriction?if Yes how do I?
Any update?