I recently discovered that "tstats" is returning sourcetypes which do not exist.
Query:
| tstats values(sourcetype) where index=* by index
This returns a list of sourcetypes grouped by index. While it appears to be mostly accurate, some sourcetypes which are returned for a given index do not exist. For example, the sourcetype "WinEventLog:System" is returned for myindex, but the following query produces zero results:
index=myindex sourcetype="WinEventLog:System"
This is the case for multiple indexes.
If my understanding of "tstats" is correct, it works by only analyzing indexed fields which are stored in the tsidx files. If no events exist with a given sourcetype for a specific index, how could that value have possibly been saved in the tsidx files?
... View more