The preferred approach is tstats , because tstats operates against indexed metadata rather than requiring Splunk to retrieve and process every matching raw event. A conceptual implementation is:
| tstats values(sourcetype) WHERE index=* BY index
This produces one result per visible index and lists the sourcetypes associated with each index. It is significantly more efficient than executing:
index=* | stats ...
because the latter can require broad raw-event retrieval across every searchable index. In a large security deployment containing billions of events, that difference is operationally significant.
The tstats command is particularly useful when the required information can be derived from indexed fields or accelerated data structures. Here, both index and sourcetype information can be obtained without inspecting full _raw event payloads.
The phrase " most efficient " is therefore central to the question. Several approaches may theoretically obtain similar information, but a broad raw-event search is unnecessarily expensive when indexed metadata already contains what is required.
This question appears on page 2 of the supplied material.
Study Guide topics: SPL efficiency, tstats, indexed metadata, index discovery, sourcetype inventory, search optimization.