Splunk Enterprise

Sourcetype=unknown

adivittorio
Observer

Hi Everyone,

i need an help about the following problem: during the analysis of some logs, we found that for a specific Index the Sourcetype had the only value Unknown.
The first question we asked ourselves was that there could have been some App or Add-on that probably did not match the data well, but neither was present.
Subsequently we tried to see if there could be some missing value at the files.conf level, but even in this case we found no problems.
So what could be the reason why for that specific Index the Sourcetype only has that value?

Labels (1)
0 Karma

KendallW
Contributor

How is this data being input to Splunk? 

You might start by checking the splunkd.log for any parsing errors or warnings.
You can also check which props settings are applied to the specific sourcetype using btool on the receiving Splunk indexer/forwarder:
$SPLUNK_HOME/bin/splunk cmd btool props list <sourcetype>

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...