We have a centalized Kinesis stream to ingest AWS Cloudwatch log groups from multiple AWS accounts with this setup https://docs.splunk.com/Documentation/AddOns/released/AWS/Kinesis.
The source showing up in Splunk in this case is the centralized account, and not from the origin source. Anyone has suggestion how the origin source AWS account can also be sent to Splunk?