In Splunk, I added an AWS add-on and tried to get data from AWS S3. While creating the input, it took the sourcetype as aws:s3:csv by default, and I was receiving the data properly. However, I accidentally changed the configuration for the aws:s3:csv sourcetype, and now the logs are not being received correctly. Can anyone help me by providing the default configuration for this sourcetype?"
You should be able to remove your local changes by deleting local/props.conf from the AWS add-on directory and restarting Splunk. If you changed default/props.conf (never advised) then re-installing the add-on will restore the defaults.