Hi
I am having 4 and half years of experience on Splunk and have worked on both admin and devlopment.
The approach I would use is will check sourcetype is correct or not..
Since, data is getting indexed but without parsing, so there may be issue with sourcetype.
For more details, pls discuss on chat.
Thanks,
Harshit