Splunk search for Indexes by sourcetype
Copy
| tstats values(sourcetype) as sourcetype WHERE index=* OR index=_* by index
This search will list all sourcetypes and the indexes they are found within. As written this search will search both internal and non-internal indexes. Depending on your needs it may make more sense to search only non-internal indexes.