How to map logs received from multiple hosts on the same local port to the correct sourcetype and index.
The Splunk data input UDP:514 receives events from the following devices:
10.0.0.1: A Netfilter firewall10.0.0.2: A Squid proxy instance (1/2)10.0.0.3: A Squid proxy instance (2/2)
We want to separate logs comming from the Firewall (10.0.0.1) and the Proxies (10.0.0.2 and 10.0.0.3):