We have turned on the cribl internal metrics source and are receiving all the metrics data in Splunk via HEC. The only metric we are not receiving is cribl.logstream.sourcetype.in_bytes. We are receiving out_bytes.
Does anyone know the reason for this?
Are you setting the Sourcetype in a Pipeline? If the data does not have a Sourcetype as it’s coming into Stream we cannot get the sourcetype.in_bytes.
Hello, we are setting the sourcetype in the source configuration:
Source → Configure → Processing Settings → Fields
Should we move it to the pipeline instead?