When a valid sourcetype is not showing up in "Data Summary" under "sourcetypes", what does it mean, and how do I get it to show up?
The sourcetype in question can be searched; there's nothing about that particular sourcetype in "health checks".
One other place where the sourcetype does not show up: Settings - Add Data. Whether I am uploading a file or setting up a file watcher, the sourcetype isn't there among the choices to assign the new data to.
Splunk Enterprise 8.1, clustered indexers, single SH. A Deployment Server is used to distribute SUF configurations.
P.S. This is related to my other recent question, "troubleshooting props.conf".