Splunk Enterprise

Sourcetype=unknown

adivittorio
Observer

Hi Everyone,

i need an help about the following problem: during the analysis of some logs, we found that for a specific Index the Sourcetype had the only value Unknown.
The first question we asked ourselves was that there could have been some App or Add-on that probably did not match the data well, but neither was present.
Subsequently we tried to see if there could be some missing value at the files.conf level, but even in this case we found no problems.
So what could be the reason why for that specific Index the Sourcetype only has that value?

Labels (2)
0 Karma

KendallW
Communicator

How is this data being input to Splunk? 

You might start by checking the splunkd.log for any parsing errors or warnings.
You can also check which props settings are applied to the specific sourcetype using btool on the receiving Splunk indexer/forwarder:
$SPLUNK_HOME/bin/splunk cmd btool props list <sourcetype>

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...