Getting Data In

Sourcetype not searcheable

TiagoTLD1
Communicator

Hello,

I am facing this behaviour: when searching for thin index, I see events of sourcetype=broker, like shown in the image below.

alt text

When searching only for sourcetype=broker, no event shows up:

alt text

Any idea why?

0 Karma
1 Solution

TiagoTLD1
Communicator

Thanks to @joao_amorim

Found my mistake:

[broker]
DEST_KEY = MetaData:Sourcetype
REGEX = (B1)
FORMAT = sourcetype::broker

View solution in original post

0 Karma

TiagoTLD1
Communicator

Thanks to @joao_amorim

Found my mistake:

[broker]
DEST_KEY = MetaData:Sourcetype
REGEX = (B1)
FORMAT = sourcetype::broker

0 Karma

amirrashid
New Member

@TiagoTLD1

Can u elaborate how u fix this issue as i facing the same issue and i am unable to understand what u actually did to get the results by source type.

0 Karma

TiagoTLD1
Communicator

Agree on that, but what about if the search "index=esi_tests sourcetype=broker" also does not return any values?

0 Karma

andrey2007
Contributor

Can you add sourcetype value using field picker to your search?

0 Karma

TiagoTLD1
Communicator

Yes I did that in my splunk. Also, to prevent hidden spaces in my sourcetype name, I used this:

index=esi_tests | search sourcetype=b*.

Also got no results

0 Karma

andrey2007
Contributor

Hello, TiagoTLD1
By default splunk searches index=main (default index)
so it may be the reason of such behavior

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...