Yes I did that in my splunk. Also, to prevent hidden spaces in my sourcetype name, I used this:
index=esi_tests | search sourcetype=b*.
Also got no results
Thanks to @joao_amorim
Found my mistake:
DEST_KEY = MetaData:Sourcetype
REGEX = (B1)
FORMAT = sourcetype::broker
Can u elaborate how u fix this issue as i facing the same issue and i am unable to understand what u actually did to get the results by source type.