I have the exact same issue as the original poster and adding this stanzas in my udp input still do not automatically extract the data at index time.
As you mentionned, it does only appears when receiving data through UDP, and directly using a transmitter without going by UDP to send the same data will allow the fields to be automatically extracted.
Peculiar enough, using a manual non-referenced sourcetype for the UDP port does extract fields at index time, presumably by automatic lookup of the data by Splunk, regardless of if no_appending_timestamp is set. I would be interrested to know what further reasons would prevent the UDP configuration to to cater for extraction at index time.
... View more