I am facing this behaviour: when searching for thin index, I see events of sourcetype=broker, like shown in the image below.
When searching only for sourcetype=broker, no event shows up:
Any idea why?
Thanks to @joao_amorim
Found my mistake:
DEST_KEY = MetaData:Sourcetype
REGEX = (B1)
FORMAT = sourcetype::broker
View solution in original post
Can u elaborate how u fix this issue as i facing the same issue and i am unable to understand what u actually did to get the results by source type.
Agree on that, but what about if the search "index=esi_tests sourcetype=broker" also does not return any values?
Can you add sourcetype value using field picker to your search?
Yes I did that in my splunk. Also, to prevent hidden spaces in my sourcetype name, I used this:
index=esi_tests | search sourcetype=b*.
Also got no results
By default splunk searches index=main (default index)
so it may be the reason of such behavior