|
It is currently possible to setup field extractions based on an I recently notice the following message in my Message:
However I'm unable to find the related documentation. Anyone know the official answer to whether or not this feature is truly going away, and how soon? Would the message be more accurately stated: "searching for extracted fields based on eventtype is not supported during the main search"? Or is there some other meaning here? I get that technically field extractions based on eventtypes is a complex and potentially confusing feature. I have many different types of events with unique field extractions for a single source/sourcetype; so I'm not sure what the recommendation is on how to replace my existing eventtype-based field extractions.... |
|
We intend to leave the feature in in its "half-working" mode until we fix it or provide a better technique for extracting fields based on a dynamic condition. You are correct in saying that the message is more accurately stated as that you can't search for eventtype-extracted fields. |
