I am currently migrating to the cloud but struggling to get the data in the cloud correctly. I have a Kiwi sylog server and a forwarder that is getting the data to the cloud, but it shows up with the incorrect host and source type. I have edited the inputs.conf to fix the source type to syslog, and that changes the hostname from the ip address of the syslog server to the facility in the message. I just need it to go one tab to the right.
Any ideas? Below is an example of how the data is formatted when sent from Kiwi.
2018-11-06 16:20:23 Local7.Notice 10.1.111.1
... View more