Splunk Enterprise

Sourcetype=unknown

adivittorio
Observer

Hi Everyone,

i need an help about the following problem: during the analysis of some logs, we found that for a specific Index the Sourcetype had the only value Unknown.
The first question we asked ourselves was that there could have been some App or Add-on that probably did not match the data well, but neither was present.
Subsequently we tried to see if there could be some missing value at the files.conf level, but even in this case we found no problems.
So what could be the reason why for that specific Index the Sourcetype only has that value?

Labels (1)
0 Karma

KendallW
Contributor

How is this data being input to Splunk? 

You might start by checking the splunkd.log for any parsing errors or warnings.
You can also check which props settings are applied to the specific sourcetype using btool on the receiving Splunk indexer/forwarder:
$SPLUNK_HOME/bin/splunk cmd btool props list <sourcetype>

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...