Hi Everyone,
i need an help about the following problem: during the analysis of some logs, we found that for a specific Index the Sourcetype had the only value Unknown.
The first question we asked ourselves was that there could have been some App or Add-on that probably did not match the data well, but neither was present.
Subsequently we tried to see if there could be some missing value at the files.conf level, but even in this case we found no problems.
So what could be the reason why for that specific Index the Sourcetype only has that value?
How is this data being input to Splunk?
You might start by checking the splunkd.log for any parsing errors or warnings.
You can also check which props settings are applied to the specific sourcetype using btool on the receiving Splunk indexer/forwarder:
$SPLUNK_HOME/bin/splunk cmd btool props list <sourcetype>