I don't know of any way to do this from the GUI. You may need to get into the backend to update the app.
1) Find where your current inputs.conf file is located on the server. The best place to look is /opt/splunk/etc/apps/search/local/input.conf for linux.
2)Find the stanza that starts like this:
[tcp://:514]
3) Above that put in a new stanza that looks like this.
[tcp://<put server ip here>:514]
index = <new index name here>
4) Restart splunk from the webui
You may need to add or removed fields to get the desired results. Here is the documentation page.
http://docs.splunk.com/Documentation/Splunk/7.2.0/Admin/Inputsconf#inputs.conf.example
... View more