1) Is that it is not supported to create extractor from the All Event stream?
I created some custom fields from Alert’s event definition, but I can’t see any value from the field “fields”, please see the image below. Is this also one of the limitations?
the processing pipelines does not work on the event and system events stream as this messages does not have the same message flow as a message that is ingested via your inputs.
That is the reason you can’t created extractors here or make a processing pipeline work on that messages.