Configuration Issues
Issue:
Sourcetype is not working for CSV data, when it is added to Indexer.
Root cause:
For Structured data, the parsing happens at Universal Forwarder(UF) itself, so the sourcetype should be configured at UF itself.
Solution:
Configure the sourcetype in Universal Forwarder for CSV Data alone & Restart the Splunk.